The MIT license and absence of install-time scripts are reassuring. The minimal project has no tests or security scanning, and the repository offers little evidence of active maintenance or clear package ownership.
38%
Total Score
0
50
100
Only two releases exist, with none in the last seven years and the latest published in September 2019. This is strong evidence of abandonment risk for a package a developer would depend on.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of current maintenance.
The package includes a README entry, but it is empty and the package and repository contain no tests or changelog. Missing tests and changelog are normal for published artifacts, while the empty README reduces consumer transparency.
The repository name does not match the package name, and no README mention was found. A monorepo mismatch can be ordinary, but with no confirming README reference this weakens confidence that the repository clearly represents this package.
Composer is used for the build, but no security scanning tools are configured. For a small library this is a meaningful maintenance and review gap, though it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
chargely/chargify-sdk-php Version ^0.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.