Clear licensing, tests, a changelog, and release notes make the package easier to assess. Its dependency set is moderate and it has no install-time scripts.
42%
Total Score
50
79
75
The package has 21 releases since 2017, but none in the last 12 months; its latest release was about 8 years ago. This indicates prolonged abandonment risk despite an earlier rapid release cadence.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the long release gap and leaving current maintenance capacity unproven.
There were 2 open issues and no issue or pull-request activity in the last month. This is consistent with an inactive project, though the small issue count limits the severity of the concern.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest hygiene gap rather than evidence of unsafe code.
The repository has no security policy, reducing transparency about vulnerability reporting and response for a package that has been inactive for years.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3.5 | — | — |
jschaedl/iban Version ^1.3 | — | — |
doctrine/collections Version ^1.3 | — | — |
ulabox/nif-validator Version ^1.2 | — | — |
keyvanakbary/slugifier Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.