Usable with caveats: the package is small but clearly maintained, licensed, tested, and not deprecated. It has only one release, and all recent repository work comes from one contributor, so maturity and continuity remain limited.
72%
Total Score
67
100
81
88
The registry namespace and repository are owned by the same individual, and the repository is not organization-backed. That matches the single-maintainer activity and leaves limited visible organizational redundancy.
The package is only 29 days old and has one release, so there is not enough history to demonstrate long-term maintenance or release stability.
One contributor made all 9 commits in the last 3 months, creating a meaningful continuity risk if that maintainer becomes unavailable. The repository is user-owned rather than organization-backed, so there is no provided evidence of an institutional handoff path.
Composer is used as a build tool, which fits the PHP package, but no security scanning tools were detected, leaving security-process transparency limited.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented. This is a hygiene gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/http-client Version ^7.2 | — | — |
willdurand/geocoder Version ^4.0 || ^5.0 | — | — |
geocoder-php/common-http Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.