The package includes a README, tests, and a focused dependency set. Organization ownership and a non-archived repository provide some continuity, but maintenance evidence is thin.
42%
Total Score
50
100
69
75
The latest release was published in December 2017, and there have been no releases in the past 12 months. Seven releases in the first few weeks show initial activity but do not offset the subsequent multi-year gap.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and indicating little evidence of ongoing maintenance.
Neither the package nor the linked repository declares or contains a recognized license file. This creates a material transparency and adoption risk for downstream users.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide little external evidence of adoption or community support.
Composer is used as the build tool, which is appropriate for this package, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/valitron Version * | — | — |
drewm/mailchimp-api Version * | — | — |
patrickgalbraith/web2lead Version dev-master | — | — |
campaignmonitor/createsend-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.