The repository has organization backing, tests, and a usable README, but no recent commits and an MIT file conflicts with the proprietary declaration. Its 0.0.x status and absent security policy add uncertainty.
43%
Total Score
75
60
100
Only two releases exist, and none were published in the last 12 months; the latest release is over six years old, which indicates substantial abandonment risk.
The manifest declares the package proprietary while an MIT license file is present in the artifact. The mismatch creates uncertainty about the terms consumers may rely on.
The repository recorded zero commits and zero active maintainers in the last three months, providing no evidence of current maintenance capacity.
Version 0.0.2 is an early, non-stable release, so compatibility and long-term support are less certain than for a stable major version.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^4.1 | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.