There is no security policy or automated security scanning, and the repository has only seven stars. MIT licensing, a matching repository, and a usable README provide some transparency.
42%
Total Score
0
75
75
The latest release was published in August 2018, and there have been no releases in the last 12 months. This long release gap is a strong abandonment concern for a library that retrieves current exchange-rate data.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with the old latest release, this indicates no recent maintenance capacity.
The repository has seven stars, two forks, and no watchers. Low adoption is supporting evidence of a small project, though popularity alone does not make a package unhealthy.
Composer is used for builds, which is appropriate, but no security scanning tools are configured. That leaves a meaningful supply-chain hygiene gap.
The repository has no security policy. This reduces transparency about how vulnerabilities are reported and handled, although it is not by itself evidence of abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^6.3 | — | — |
symfony/dom-crawler Version ^4.1 | — | — |
symfony/css-selector Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.