The package has broad runtime dependencies and no repository security policy, while its README contains no readable content. Apache licensing, tests, a stable release line, and a long release history provide useful support.
58%
Total Score
50
50
83
83
The package declares 20 runtime dependencies, including cloud, authentication, database, and messaging libraries. This broad dependency surface increases maintenance and update burden.
Tests are present in both the artifact and repository, and the package includes a README, but the recorded README length is 0 characters and there is no changelog. The tests compensate for some transparency gap, while the empty README still weakens consumer guidance.
The package has 238 releases since June 2019, but none in the last 12 months; that recent pause is a meaningful maintenance concern despite the long history.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which weakens evidence of ongoing maintenance for a library with many integrations.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.7 | — | — |
phoole/event Version ^1.1 | — | — |
geoip2/geoip2 Version ~2.0 | — | — |
php-di/php-di Version ^6.1 | — | — |
aws/aws-sdk-php Version ^3.81 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.