The repository has a security policy and no install-time scripts. Resolve the licensing mismatch before adoption; the placeholder documentation and limited maintenance activity suggest weak ongoing support.
52%
Total Score
75
69
100
The manifest declares MIT, but the artifact license file is detected as GPL-2.0. Although a license file is present, the mismatch creates material uncertainty about the terms developers may receive.
The package includes a README, and the repository has tests, but the published README is only 464 characters and remains an unfilled template with placeholder installation and usage content. That weakens consumer transparency for a library.
All four releases occurred within roughly six hours on October 30, 2025, followed by no later release despite the package being about 11 months old. This suggests an initial burst rather than an established release cadence.
The repository recorded zero commits and zero active maintainers during the last three months. With no newer release activity to compensate, this is evidence of limited ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance-process gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ext/support Version ^1.0 | — | — |
ext/exception Version ^1.0.3 | — | — |
psr/http-message Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.10 | — | — |
composer/ca-bundle Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.