The README and comprehensive tests make the package easier to evaluate. Its old PHP 5.4 target and license mismatch add adoption friction, while the repository is not archived.
42%
Total Score
0
100
67
75
Only four releases were published, all concentrated in October 2019, with no release in nearly seven years. This is strong evidence of abandonment risk for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
The package declares MIT, but its artifact license file is detected as Apache-2.0. A license file exists and the repository also has one, but the mismatch creates legal ambiguity.
Composer is used as the build tool, but no security scanning tooling is configured. The missing scanning is a modest transparency gap, not evidence of an unsafe release by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters more for a maintained dependency, but still weakens transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
hongyukeji/plugin-package Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.