Its declared proprietary license provides a clear legal status, but there is no security policy or automated security scanning. The tiny repository also offers little evidence of broader support.
35%
Total Score
0
60
50
Only two releases were published, with the latest released over six years ago and none in the last 12 months. This is strong evidence of abandonment risk for a package consumers may need to maintain.
The repository recorded no commits and no active maintainers in the last three months, reinforcing that development has stopped rather than merely slowed.
The repository has zero stars and forks and only one watcher. Popularity is not required for a healthy package, but these counters provide no supporting evidence of community adoption or review.
Composer is used for builds, but no security scanning tools are present. That leaves a meaningful maintenance and review gap for a package handling external service integration.
The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/recaptcha Version ^1.2 | — | — |
guzzlehttp/guzzle Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.