The package is licensed, matches its source repository, and uses no install-time scripts. Its small codebase and straightforward dependency set do not offset the lack of current maintenance.
40%
Total Score
50
100
63
83
The latest release was over 9 years ago, with only two releases and none in the last 12 months. This is strong evidence of abandonment for a package intended to remain a maintained dependency.
There were no commits and no active maintainers in the last 3 months, consistent with a repository whose last push was over 9 years ago. This materially increases abandonment risk.
The artifact includes a README entry, but it is empty and the package has no tests or changelog. Missing tests and changelog are normal for published artifacts; the empty README is a minor consumer-transparency gap.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these values provide no community-maintenance buffer.
Composer is used as a build tool, but no security scanning tools are present. The missing scanning is a hygiene gap, not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
google/recaptcha Version ~1.1 | — | — |
dapphp/securimage Version ^3.6 | — | — |
intervention/image Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.