The package includes a usable README, repository tests, and release notes for this version. Its runtime dependency list is unusual for a library, and no license is declared or included.
38%
Total Score
0
50
50
100
This package has only one release, published more than 8 years ago, with no releases in the last 12 months. That strongly indicates abandonment risk.
The repository recorded no commits and no active maintainers in the last 3 months, providing no evidence of ongoing maintenance to offset the old release history.
The package declares phpunit/phpunit as its sole runtime dependency and has no development dependencies, an unusual layout that may increase consumer dependency risk.
No license is declared, and neither the package artifact nor the collected repository contains a license file. The README mentions MIT, but the collected license evidence does not verify it.
Composer is used for builds, but no security scanning tools were detected. This is a transparency and hygiene gap, though it does not outweigh the maintenance concerns by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.