The project has been dormant for more than four years, with no recent maintenance or security tooling. Its small scope and clear release notes reduce complexity, but the outdated installation example adds friction for consumers.
42%
Total Score
0
64
75
The package has had no release in more than four years and has only three releases, all clustered on one day. This is strong evidence of abandonment risk despite the stable v3.0 version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No provided signal shows compensating maintenance activity.
A README and release notes are present, which provide basic consumer guidance and document this version. However, the README still instructs users to install v2.0 while assessing v3.0, reducing transparency and usability.
The repository has zero stars and forks and only one watcher, providing little evidence of community review or adoption. Popularity is supporting evidence rather than a verdict, so this remains a secondary concern.
Composer is used for the build, but the repository has no security-scanning tools. For a package handling form captcha validation, this is a modest maintenance and review gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.