The stable release, explicit GPL-3.0-or-later license, and lack of install-time scripts reduce adoption friction. The tiny artifact and missing security process leave limited transparency for a library.
43%
Total Score
0
71
67
Only two releases were published, both in August 2022, with none in the last four years. This is strong evidence of abandonment risk for a package intended for API integration.
The repository had no commits and no active maintainers in the last three months, consistent with the long gap since its last push. This materially increases the risk that defects and compatibility issues will remain unaddressed.
The artifact and repository each contain only three files: .DS_Store, composer.json, and finvu.php. That may be enough for a very small wrapper, but it provides little visible documentation, testing, or project structure for an API library.
The release includes GitHub release notes stating that a variable name changed, which documents this version. However, it has no README, tests, or changelog, leaving consumers with little integration guidance or visible validation.
Composer is used as the build tool, but no security-scanning tooling is present. This is a modest transparency and maintenance gap, not evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.2 | — | — |
composer/installers Version ~1.0 | — | — |
oomphinc/composer-installers-extender Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.