The four-file implementation and single PHP runtime dependency keep the technical surface small. The matching repository is not archived, but it provides little evidence of ongoing care or security oversight.
30%
Total Score
0
50
50
The package has made only three releases, all in 2016, with no release in roughly 10 years. That is strong evidence of abandonment for a dependency whose compatibility may need maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving no evidence of current maintenance.
No license is declared, and neither the package nor repository contains a license file. This creates a material legal and transparency concern for adoption.
The artifact has no README, which makes a small library harder to integrate; the absence of tests and a changelog is normal packaging practice and is not treated as a gap here.
Composer is used as the build tool, which is appropriate, but no security-scanning tooling is reported. This is a modest oversight concern rather than evidence of unsafe behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.