Clear licensing, tests, and no install-time scripts reduce adoption friction and operational risk. The small, organization-backed project is not archived or deprecated, but its narrow purpose and external PECL requirement limit its reach.
60%
Total Score
75
81
75
The package has 11 releases but none in the last 12 months; its latest release was over five years ago, which is a meaningful maintenance concern for a dependency.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive since 2021 and increasing abandonment risk.
The repository name does not match the package name and its README does not mention the package, so the linkage is less transparent and the repository may not clearly belong to this release.
The repository uses Composer build tooling, but no security-scanning tools were detected. For this small interface package this is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a minor transparency concern for a package that depends on an external PECL extension.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.