Tests and organization backing provide useful support for the small library. Maintenance evidence is thin, with only one release about three years ago and no commits in the last three months; workflow references are also unpinned.
52%
Total Score
75
100
81
50
The package includes tests, and the absence of a packaged changelog is normal for a published PHP library. The missing README is a minor consumer-documentation gap.
The package has made only one release, on June 28, 2023, with none in the last three years. That is meaningful evidence of limited release maintenance, although the repository was pushed more recently than the registry release.
There were zero commits and zero active maintainers in the last three months. Combined with the single-release history, this raises concern about ongoing maintenance capacity.
The repository uses Make and Composer, but no security-scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe.
No security policy is present in the repository, reducing transparency for reporting and handling vulnerabilities, though this does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fond-of-oryx/jellyfish-sales-order-extension Version ^1.0.0 || ^2.0.0 | — | — |
fond-of-impala/conditional-availability-sales-connector Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.