The package has a README, a declared Apache-2.0 license, and an organization-owned repository. It lacks a security policy and security scanning, while its sole release and repository activity are more than six years old.
42%
Total Score
50
75
50
This is the package's only release, published more than six years ago, with no releases in the last 12 months. That strongly suggests abandonment for a dependency intended to integrate with a changing service.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No newer activity compensates for this maintenance risk.
Composer is used for builds, which is appropriate, but no security-scanning tools are configured. The absence of scanning is a modest hygiene concern rather than evidence of a vulnerability.
The repository has no security policy, so there is no documented channel or process for reporting and handling vulnerabilities. This adds a transparency gap to an otherwise inactive project.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.133 | — | — |
monolog/monolog Version ~1.7 | — | — |
composer/installers Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.