The MIT license, tests, README, and organization-owned matching repository provide a solid starting point. There is no security policy or scanning, and its two releases arrived within about two hours, so long-term maintenance remains unproven.
68%
Total Score
75
88
75
This is a very new package, with only two releases published within about two hours and no longer maintenance history to evaluate. That limits confidence in its durability rather than proving abandonment.
The repository records no commits and no active maintainers during the last three months. Because the package itself is less than a day old, this is mainly an unproven-maintenance concern, not strong evidence of abandonment.
Composer build tooling is present, but no security-scanning tool was detected, leaving repository security hygiene less demonstrated.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
kodhe/cache Version ^1.0 || ^2.0 | — | — |
kodhe/session Version ^1.0 || ^2.0 | — | — |
kodhe/validation Version ^1.0 || ^2.0 | — | — |
paragonie/random_compat Version ^9.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.