Library for confirmation tokens
63%
Total Score
caution
Usable with caveats: only one old registry release, despite a maintained and well-documented repository.
The package has only one release, published in October 2016, with no releases in the last 12 months. That makes version maintenance and compatibility less certain.
There were no commits or active maintainers in the three months before collection. The recent repository push is a compensating sign, but the short-term inactivity still weakens evidence of ongoing development.
The repository uses Composer build tooling, but no security scanning tools were detected. For a small PHP library this is a modest transparency gap rather than a severe risk.
The repository has no security policy. That leaves vulnerability reporting and response expectations unspecified, although it does not by itself indicate abandonment.
Version 0.0.1 is not a prerelease, but it remains an early, unreleased-beyond-0.x version after a single registry publication. This limits evidence of mature release practices.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.