Clear documentation, tests, and a declared MIT license support adoption. Security-process and workflow-pinning gaps leave more maintenance risk than a mature dependency should have.
70%
Total Score
50
50
89
50
Eight runtime dependencies create a moderate supply-chain surface for a PHP library, but the profile is explicit and includes the expected PHP runtime declaration.
All three recent commits came from one contributor, so the project is exposed to a single-person maintenance failure despite its recent activity.
Three commits were made in the last 3 months, with one active maintainer; this is current activity, but the maintenance base is narrow.
The repository has 1 star and no forks, indicating limited visible adoption; popularity is supporting evidence only, so this modestly lowers confidence rather than determining the verdict.
Composer build tooling is present, but no security-scanning tool was detected, leaving a transparency and vulnerability-monitoring gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cocur/slugify Version ^4.7.1 | — | — |
gettext/gettext Version ^5.7.3 | — | — |
vlucas/phpdotenv Version ^5.6.3 | — | — |
vielhuber/dbhelper Version ^2.4.6 | — | — |
vielhuber/excelhelper Version ^1.3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.