This release appears healthy and suitable to depend on: it has a stable major version, 47 releases over nearly four years, 11 releases in the last 12 months, and a recent release cadence, while the repository remains active and unarchived with 42 commits and five merged pull requests in the latest month. The package and repository include substantial documentation, tests, a changelog, examples, and a clear MIT license. The main reservations are a small two-person active contributor base, no repository security policy, and an Actions workflow without explicitly declared top-level token permissions; these are meaningful hygiene gaps but do not outweigh the strong maintenance and packaging evidence.
86%
Total Score
80
100
94
80
Only one account has registry publish access, which is a modest publishing continuity risk; however, registry access does not measure actual maintenance activity and the repository shows two active contributors.
The repository is owned by a user account rather than an organization, so there is no organization-level maintenance handoff evidence; nevertheless, two contributors are actively committing.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a security-process gap, though it is not evidence of abandonment and other workflow checks are clean.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This lowers transparency but is not by itself evidence that the package is unsafe to depend on.
The only workflow lacks top-level token permissions declarations, so its default GitHub Actions token scope is not explicitly constrained. No top-level write permissions were observed, making this a hygiene caution rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version >=0.11 <0.15 | — | — |
php-ds/php-ds Version ^1.4 | — | — |
simplito/bn-php Version ^1.1.4 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
guzzlehttp/guzzle Version ^7.15.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.