The package is clearly identified, licensed, and includes tests, with no install scripts or registry deprecation. Its source has had no commits for over eight years and shows no security scanning, so future compatibility support is uncertain.
42%
Total Score
25
71
100
The package has 11 releases but none in more than eight years; the latest release was published in April 2018. This is strong evidence of abandonment risk for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The project may be stable, but there is no observed maintenance capacity for current compatibility issues.
Only one registry maintainer is listed. For this user-owned project, that indicates a thin publishing base rather than organization-backed redundancy.
The repository has zero stars and forks and only one watcher, providing little evidence of an active user or contributor community. Popularity is supporting evidence rather than decisive on its own, but it reinforces the maintenance concern.
Composer is used for the build, but no security-scanning tool was detected. For an old, inactive package this leaves less evidence of ongoing security hygiene, though it is not severe by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-foundation Version >=2.1 | — | — |
hocnt84/oauth2-server-php Version ^1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.