The repository includes tests, release notes, and a stable MIT-licensed release backed by an organization. Maintenance is quiet, with no commits in the last 3 months, and the repository does not clearly identify this package in its name or README.
58%
Total Score
75
81
83
The package has existed since 2019 but has only 3 releases, with no releases in the last 12 months and a median interval of about 2.9 years. The latest release in May 2025 shows it is not abandoned outright, but the cadence is very slow.
There were no commits and no active maintainers in the last 3 months. Combined with the slow release history, this indicates limited current maintenance capacity.
The repository name does not match the package name and its README does not mention the package. Although this could be a subpackage or naming variation, the lack of an explicit connection makes package provenance less clear.
The repository uses Composer for builds, but no security scanning tool was detected. For a small PHP library this is a modest transparency and maintenance gap, not a severe risk by itself.
The repository has no security policy. That weakens vulnerability-reporting transparency, although the package's tests and recent release provide some compensating project evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
marc-mabe/php-enum Version ^2.0 || ^3.0 | — | — |
ltd-beget/stringstream Version ^v2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.