Usable with caveats: it has recent stable releases, tests, a matching repository, and clear licensing. However, it is maintained by one publisher with no commits in the last three months and no security policy, so long-term maintenance capacity is limited.
70%
Total Score
63
100
89
83
Only one account has registry publishing access. That is a real continuity risk for a user-owned project, although the recent release history shows the maintainer is still publishing.
The package namespace and repository owner match, but the project is user-owned rather than organization-backed, so continuity depends on a single individual.
The repository recorded zero commits and zero active maintainers in the last three months. Recent releases partly compensate, but this still leaves limited evidence of ongoing development between releases.
The repository has one star and two forks, indicating limited adoption. Popularity is only supporting evidence, so this modestly lowers confidence in maturity but does not make the package unsafe by itself.
Composer build tooling is present, but no security scanning tool was detected. For this small provider this is a hygiene gap rather than a severe supply-chain risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^6.4 | — | — |
willdurand/geocoder Version ^5.0 | — | — |
geocoder-php/common-http Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.