It has a stable version and is not marked deprecated, but consumer documentation and security practices are weak. Pinning this old release leaves little evidence of ongoing support.
32%
Total Score
0
57
50
The package has only 3 releases, with the latest published in September 2018 and none in the last 12 months. This indicates prolonged abandonment risk for a dependency.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with the package's long release gap and providing no evidence of current maintenance.
No declared license, license file, or repository license file was detected. This creates a real adoption and legal-transparency concern.
The artifact has no README, while absent tests and changelog are normal packaging practice. Because this is an application package with integration-oriented files, the missing consumer documentation is still a minor transparency gap.
The linked repository name does not match the package name, and no README package mention was available. That raises some uncertainty about whether the repository directly belongs to this package.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.5 | — | — |
gnixsung/sungswoole Version v1.0 | — | — |
easyswoole/swoole-ide-helper Version ^1.0 | — | — |
joshcam/mysqli-database-class Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.