The library has seen no release for nearly four years and no recent repository commits, so compatibility and maintenance support are uncertain. MIT licensing and organization backing help, but the empty README and lack of tests or security scanning leave limited evidence for dependable integration.
55%
Total Score
75
100
75
75
The artifact includes a README entry, but it has zero recorded content; the source repository has no tests or changelog. Missing tests and changelog are normal packaging practice, while an empty consumer-facing README is a minor transparency gap.
The latest release was nearly four years ago, with no releases in the last 12 months. This is a meaningful maintenance concern, though the package has seven releases and is not deprecated.
There were no commits and no active maintainers in the three months before collection. Combined with the old latest release, this is strong evidence of inactive maintenance.
The repository uses Composer, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unsafe.
No security policy was found in the repository, leaving vulnerability-reporting expectations unclear. This lowers transparency but is not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
gipfl/curl Version >=0.1.1 | — | — |
gipfl/json Version >=0.2 | — | — |
react/event-loop Version >=1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.