The package is licensed, documented, tested, and has no install-time scripts. Its organization-backed project has a small audience and no security policy, which limits assurance for long-term use.
58%
Total Score
50
69
75
The package has 25 releases, but none in the last 12 months; the latest release was published about 2 years and 7 months ago. This is strong evidence of stalled maintenance despite the earlier release burst.
There were no commits and no active maintainers in the last 3 months, consistent with the latest push being about 2 years and 7 months ago. This materially raises abandonment risk.
The repository has only 2 stars, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but this provides little external evidence of broad adoption or review.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. For a package that crawls web content and uses network-related extensions, this reduces transparency around vulnerability reporting and response.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
adhocore/cli Version ^v1.0.0 | — | — |
ixnode/php-container Version ^0.1.22 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.