The package has a clear README, a small and understandable file layout, and a recent release. Limited security tooling and a single active contributor leave less evidence of resilience.
68%
Total Score
50
83
75
All recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
There was one commit in the last three months, showing some current activity but only a thin maintenance signal.
The repository has zero stars and forks and only two watchers. Popularity is not decisive, but this provides little supporting evidence of broad review or adoption.
Composer build tooling is present, but no security scanning tools were detected, leaving less automated oversight for a package focused on vulnerability auditing.
The repository has no security policy, which reduces clarity about how users should report vulnerabilities and how security issues are handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.4||^7.5 | — | — |
jean85/pretty-package-versions Version ^2.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.