The MIT license, detailed README, and release notes for this version make the package easier to understand and adopt. Its small community and missing security policy leave less evidence of ongoing support.
58%
Total Score
25
100
83
75
The package has had no release in more than 4 years, with zero releases in the last 12 months. This is a meaningful maintenance concern, although the repository is not archived and the package has a stable release.
There were no commits or active maintainers in the last 3 months, consistent with a project whose latest repository activity is years old. This substantially increases abandonment risk.
There is only one open issue and no recent issue or pull-request activity. The low issue count is neutral, while the lack of recent activity offers little evidence of active support.
Composer is used for the build, but no security scanning tools are present. This is a hygiene gap rather than evidence that the package is unsafe or abandoned.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This modestly reduces transparency for a package that handles certificates and web-service requests.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
greenter/xmldsig Version ^5.0 | — | — |
spatie/array-to-xml Version ^2.8 | — | — |
robrichards/xmlseclibs Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.