The organization-backed repository is not archived, the package includes a usable README, and its MIT license is explicit. Install-time scripts and the absence of a security policy add modest operational concerns.
58%
Total Score
100
60
50
The latest release was published over three years ago, with no releases in the last 12 months. The package has five releases overall, but this long pause materially raises abandonment risk.
The package runs pre-install and pre-update commands, increasing installation complexity and the amount of publisher code executed during dependency changes.
Composer is used as the build tool, but no security-scanning tooling is reported. The missing scanning coverage is a modest hygiene concern, while the standard build tooling is positive.
The organization-backed repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is not evidence that the package is unsafe.
Version 0.2.0 is not a prerelease, which avoids a prerelease warning, but the still-pre-1.0 version indicates a less mature compatibility commitment.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.