The package includes tests, a useful README, and a small dependency set, but its proprietary license limits straightforward reuse. The organization-backed repository remains intact, although maintenance and security practices appear thin.
58%
Total Score
75
100
71
75
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This creates a real reuse and distribution constraint for an open-source dependency.
The latest release was March 30, 2022, about 4 years and 6 months before collection, with no releases in the last 12 months. The package had a short early release cadence, but the prolonged gap raises abandonment risk.
There were no commits and no active maintainers in the last 3 months. Combined with the old latest release, this indicates that current maintenance capacity is limited.
The repository uses Composer build tooling, but no security scanning tools were detected. This is a modest security-process gap rather than evidence that the package is unsafe.
The linked repository is not archived and was last pushed on May 30, 2022. Its availability is reassuring, but the old push date does not offset the broader maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 | — | — |
pimple/pimple Version ^3.0 | — | — |
phpfastcache/phpfastcache Version ^5.0|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.