The package is small and clearly identified, with a valid MIT license and no install-time scripts. Its minimal five-file tree offers little evidence of testing or security process, so future compatibility work would fall to consumers.
38%
Total Score
0
67
75
The last release was in April 2015, with no releases in the past 12 months. That long silence is strong evidence of abandonment risk for a dependency released over 11 years ago.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the stale release history and leaving no observed maintenance capacity.
Composer is used for the build, which is appropriate, but no security scanning tools are present. This is a modest process gap rather than a standalone dependency blocker.
The repository is not marked archived, but its last push was in April 2015. The stale activity still weighs heavily despite the repository remaining technically available.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This compounds the lack of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ~4.0 | — | — |
jolicode/jolinotif Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.