Its dependency footprint is small and install-time scripts are absent. The source matches the package, and the latest release includes release notes; these positives do not offset the limited maintenance depth.
61%
Total Score
67
100
75
75
The artifact includes a README, but it is only 10 characters long and provides almost no integration guidance. Tests and a changelog are not expected in the published artifact, while release notes for version 2.0.2 provide some documentation.
The package is 589 days old with six releases, but only one release appeared in the last 12 months. That suggests a slower maintenance pace, though the latest release is recent.
All recent commit activity comes from one contributor, creating a concentrated maintenance dependency. Organization ownership provides some ability to hand work off, which partly offsets the concentration.
The repository had one commit in the last three months, indicating limited recent maintenance activity. The current release shows the project is not entirely inactive, but the ongoing maintenance depth is thin.
The repository has no security policy. This is a modest transparency gap for a package handling CAPTCHA functionality, although it is not evidence that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeigniter4/framework Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.