Usable with caveats: it has a stable release, a recent update, clear README documentation, and organization-backed source code. The repository does not name or mention this package, and only two releases exist across roughly two years, so verify the source relationship before adopting it.
62%
Total Score
100
100
78
50
Only two releases exist across 737 days, with one release in the last 12 months and a median interval of about 646 days; the recent release helps, but the sparse cadence limits evidence of sustained maintenance.
The repository name does not match the full package name and its README does not mention the package, so the package-to-source relationship is not clearly demonstrated despite the related-looking repository name.
The repository has no stars or forks and only one watcher. This is weak supporting evidence, but popularity alone does not make a small package unhealthy.
Composer is used for the build, but no security scanning tooling is present. This is a transparency and automation gap, though not severe enough to make the package unfit on its own.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a modest transparency gap for a library dependency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version * | — | — |
foolz/sphinxql-query-builder Version ^4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.