The MIT license, clear README, and matching source tree make use and inspection easier. Its small footprint and simple Composer setup limit operational complexity, but no security tooling leaves less protection for future changes.
42%
Total Score
25
100
71
100
Only two releases were published, both in December 2017, with no release in nearly nine years. This is strong evidence that maintenance has stopped.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the long release gap and indicating no current maintenance capacity.
One registry publishing maintainer is listed. This is not inherently unhealthy for a small user-owned package, but it provides limited visible redundancy if maintenance resumes.
The repository has one star and no forks, offering little supporting evidence of broad community review or backup maintenance. Popularity is secondary to the inactive project history.
Composer is used for builds, but no security scanning tools are configured. The missing scanning reduces repository hygiene and future-change visibility, although it is not evidence of maliciousness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1.4 | — | — |
joshtronic/php-holidayapi Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.