The package includes a clear README, an Apache-2.0 license, and a matching source repository that is still available. Its small user and contributor footprint, lack of security policy or scanning, and nearly three years without repository activity make long-term support uncertain.
48%
Total Score
50
75
50
The latest release was on November 20, 2023, and there have been no releases in the last 12 months. The earlier nine-release history shows initial activity but does not offset the prolonged current inactivity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the latest release being nearly three years ago. This is strong evidence of current abandonment risk.
There are 4 open issues and 5 open pull requests, but no new or closed issues or pull requests in the last month. The unresolved queue adds to the maintenance concern.
The repository has only 2 stars, 2 forks, and 1 watcher. Low popularity is supporting evidence of a small ecosystem and limited review, but is not by itself a disqualifier.
Composer build tooling is present, but no security scanning tools are configured. That leaves fewer automated checks for a package handling authentication and SMS-related code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
flarum/core Version * | — | — |
fof/components Version ^1.0.0 | — | — |
alibabacloud/darabonba-openapi Version ^0.2.8 | — | — |
alibabacloud/dysmsapi-20170525 Version 2.0.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.