The repository remains active enough to have a recent push, tests, release notes, and matching package references. However, the registry shows no releases in over eight years, and its reported latest version predates the assessed release; there is also no security policy or scanning.
50%
Total Score
100
69
83
The package has had no release in over eight years, despite six releases early in its history. That long release gap is a substantial maintenance concern, though the repository's recent push provides some compensating evidence.
The repository has one star and two forks, indicating limited adoption. Popularity is only supporting evidence, so this modest footprint does not independently make the package unfit.
The repository uses Composer, but no security scanning tool was detected. The missing scanning is a modest transparency gap, not evidence that the release is unsafe.
No repository security policy was found. For a package handling CAPTCHA integration, this weakens the documented process for reporting and managing security issues.
The registry reports v0.3.0 as the latest version while this assessment covers v0.5.0, creating a transparency and reproducibility concern. The release is not marked prerelease, so this is not merely normal prerelease churn.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pimple/pimple Version ^3.0 | — | — |
google/recaptcha Version ^1.1 | — | — |
psr/http-message Version ^1.0 | — | — |
locomotivemtl/charcoal-config Version ~0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.