Recent releases and a matching Apache-2.0 license provide useful stability. The small codebase has limited validation and security-process evidence, reducing long-term assurance.
68%
Total Score
67
100
86
50
The artifact has no README, tests, or changelog, while the repository also reports no tests or changelog. Missing tests and project documentation reduce transparency for a reusable library, although their absence in the published artifact can be normal.
All recent activity comes from one contributor, with that contributor responsible for 100% of the single recent commit. Organization backing provides some handoff capacity, but observed maintenance remains concentrated.
The repository had one commit in the last 3 months, showing recent activity but at a low volume. This supports maintenance continuity without demonstrating a strong development pace.
Composer is used for builds, but no security scanning tools were detected. Build tooling is appropriate, while the missing security tooling leaves a modest assurance gap.
The repository has no security policy. For a reusable library this makes vulnerability reporting and maintainer response expectations less transparent.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
endroid/qr-code Version ^6.0 | — | — |
giggsey/libphonenumber-for-php Version ^8.12.35 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.