The small seven-file package has a short README, no tests, and no security policy. Its declared MIT license and release notes help, but nine runtime dependencies increase maintenance exposure for a dormant pre-1.0 project.
42%
Total Score
50
50
79
75
This seven-file helper declares nine runtime dependencies, including several project-specific packages. That creates a relatively large maintenance and compatibility surface for such a small package.
Only two releases were published, both around four years ago, with none in the last 12 months. This is strong evidence of abandonment for a package developers would depend on.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That leaves less visible assurance for a package with multiple runtime dependencies.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a hygiene gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
erusev/parsedown Version >=1.7@stable | — | — |
mailgun/mailgun-php Version >=3.5@stable | — | — |
tymfrontiers-cdn/php-data Version >=0.1@stable | — | — |
ikechukwuokalia/helper.cwapp Version >=0.1@stable | — | — |
tymfrontiers-cdn/php-validator Version >=0.1@stable | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.