The package has a large runtime dependency footprint and little repository security tooling. Its MIT licensing, stable version, active non-archived repository, and clean publishing setup provide useful safeguards.
56%
Total Score
50
50
79
83
The release declares 60 runtime dependencies and no development dependencies, creating a broad transitive maintenance and compatibility surface. This is a meaningful adoption concern for a package with extensive application functionality.
The package has 162 releases since July 2022, but no release in the last 12 months despite its latest release being in September 2025. That recent release history is outweighed by the current publication gap, which raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the absence of releases in the last year, this indicates sharply reduced maintenance activity.
The repository has one star, one fork, and one watcher, indicating a very small visible user and contributor base. Popularity is only supporting evidence, but this provides little external maintenance signal.
Composer is used for builds, but no security scanning tools are configured. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1.1.4 | — | — |
flc/dysms Version * | — | — |
pimple/pimple Version v3.3.1 | — | — |
qiniu/php-sdk Version * | — | — |
smarty/smarty Version v3.1.36 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.