The package has a matching repository, MIT licensing, a substantial README, and release notes for this version. A single maintainer, no commits since June 2021, and no security policy or scanning make future fixes and oversight uncertain.
55%
Total Score
25
70
50
The package has 16 releases over about 11 years, but none in the last 12 months; the latest registry release was in June 2021. This long period without releases materially raises abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push occurring in June 2021. The inactive codebase is the main concern for relying on a package that integrates with an evolving external service.
Only one registry publisher account is listed. With no organization backing shown and no recent commit activity, the project has limited visible continuity if that maintainer stops responding.
Composer is used for the build, which is appropriate, but no security scanning tools are present. That leaves dependency and repository-level security checks less visible.
The repository has no security policy. This reduces transparency around vulnerability reporting and response, although it is a secondary concern compared with the maintenance gap.
| Title | Versions | Severity |
|---|---|---|
CVE-2021-43678 gaoming13/wechat-php-sdk is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 1.10.2. | 0.0.0 - 1.10.2 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.