The license is clear, the package matches its repository, and installation has no lifecycle scripts. Its tiny README and absent security policy provide little additional guidance for long-term adoption.
12%
Total Score
50
50
75
Packagist marks the entire package as abandoned, with no replacement provided. This is a direct warning against taking a new dependency on the package.
The linked repository is archived and was last pushed about two months before assessment, indicating the source is no longer actively maintained.
The release includes GitHub release notes and a README, and the missing tests and changelog are normal for a published artifact. However, the README is only 29 characters, so consumer guidance is minimal.
One contributor made 100% of the recent commits. For a user-owned project with no organizational backing, this leaves maintenance dependent on a single person.
Only one commit was recorded in the last three months, showing very limited recent maintenance and reinforcing the archived status.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jayzeng/virustotalapi Version ^0.1.9 | — | — |
jord-jd/do-file-cache Version ^5.0 | — | — |
jord-jd/php-cli-progress-bar Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.