The small artifact is documented by a README and has no install-time scripts, reducing adoption and installation friction. However, it lacks a license and security policy, leaving important project transparency gaps.
15%
Total Score
0
50
75
Packagist marks the entire package as abandoned and recommends google/recaptcha instead. This is a direct warning against starting a new dependency on this package.
This package has only one release, published about 9 years ago, with no releases in the last 12 months. That indicates severe abandonment risk for a dependency.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the package's long period without releases. No compensating maintenance activity is shown.
No license is declared, and neither the package nor the linked repository contains a recognized license file. This creates a material legal and transparency gap for adoption.
The linked repository has no security policy. For a package handling reCAPTCHA integration, this leaves vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.