The five-file repository has no security scanning or policy, and its popularity is negligible. Its package identity, Composer build, and lack of install scripts provide some reassurance.
42%
Total Score
50
58
75
The package has only one release, published in November 2021, with no releases in the following four years. That is strong evidence of abandonment risk for a dependency.
The repository has had zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance capacity.
No license is declared, and neither the package nor the repository contains a license file. This creates a real adoption and redistribution concern.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide no compensating confidence for the lack of activity.
Composer is used as a build tool, which is appropriate for this package, but no security scanning tool is configured. The missing scanning is a minor transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.