The MIT license, focused README, and absence of install scripts make the package straightforward to inspect and integrate. Its last release and repository activity date to 2016, with no recent commits or security scanning, so this is effectively a dormant dependency.
38%
Total Score
0
70
75
The latest release was in April 2016, and there have been no releases in roughly 10 years. Only three releases exist, so maintenance and compatibility expectations are weak.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing long-term inactivity.
Composer build tooling is present, but no security scanning tools were detected. That limits ongoing assurance for a package handling database access.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported. This compounds the package's otherwise long-standing inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.