The matching repository, clear BSD-3-Clause licensing, and practical README improve transparency. Its old release and absent recent maintenance or security policy make long-term support doubtful.
38%
Total Score
50
71
50
This package has only one release, published about nine years ago, with no releases in the last 12 months. That strongly suggests abandonment for a dependency.
The repository has had no commits and no active maintainers in the last three months, consistent with a project that has been inactive for about nine years.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not proof of unsafe code.
The repository has no security policy, leaving no documented process for reporting and handling vulnerabilities.
Version 0.0.0 is not a stable major release, adding maturity and compatibility uncertainty alongside the package's single-release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 | — | — |
bitexpert/disco Version ^0.8 | — | — |
mongodb/mongodb Version ^1.0 | — | — |
monolog/monolog Version ^1.21 | — | — |
nikic/fast-route Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.