Its MIT license, README, and small dependency set make the contents understandable, but there is no security policy and the repository has no stars or forks. Treat it as an abandoned legacy project rather than a maintained dependency.
12%
Total Score
0
100
63
75
Packagist marks the entire package as abandoned, with no replacement specified. This is a severe adoption risk because the registry explicitly signals that maintenance has ended.
The latest release was published about six years ago, with no releases in the last 12 months. This strongly indicates the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and indicating no current maintenance activity.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counters provide no supporting evidence of community adoption or review.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest hygiene gap, and the lack of recent development makes it more difficult to compensate through ongoing checks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kreait/firebase-php Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.