The MIT license and one PHP runtime dependency make its contents easy to inspect. No security policy or scanning is present, and the repository has no workflow automation.
38%
Total Score
50
60
50
The artifact has no README, tests, or changelog; the missing tests and changelog are normal for a published artifact, but the absent README reduces consumer transparency for a library.
Only five releases appeared, all clustered on 21 September 2021, with no release in the last five years. That is strong evidence of abandonment for a package intended as a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The linked repository name does not match the package name, and no README mention was available. This creates uncertainty that the repository is the package's actual source.
Composer is used for the build, which is appropriate, but no security-scanning tool is configured. That leaves dependency and release hygiene less independently checked.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.