The package has a clear README, a declared MIT license, and a small dependency surface. Its single-person project shows no evidence of ongoing maintenance, so adopting it carries substantial abandonment risk.
36%
Total Score
50
100
69
75
The latest release was published about 10 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a package developers would depend on.
Registry publishing is controlled by one maintainer, and the linked repository is owned by the same individual. With no recent release activity, this leaves limited visible maintenance capacity.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a maintained user community.
Composer is used for builds, but no security scanning tooling is present. This is a hygiene gap, not evidence of active supply-chain harm.
The repository has no security policy. That reduces transparency for reporting and handling issues, although it is less important than the long maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ~2.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.