The package includes tests, a readable README, and an MIT license file. Composer build metadata is present, but security scanning and a security policy are absent.
36%
Total Score
0
71
75
The package is about 10 years old, with eight releases but none in the last 12 months; its latest release was published on March 24, 2016. This is strong evidence of abandonment.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long gap since the last release and indicating little current maintenance capacity.
The linked repository name does not match the package name and its README does not mention the package. That makes package-to-source ownership less transparent, even though a name mismatch can occur for subpackages.
Composer build tooling is present, which supports reproducible project practices, but no security scanning tools were detected. The missing scanning is a modest hygiene gap.
The repository has no security policy. This does not prove a vulnerability, but it reduces transparency about how security issues are reported and handled.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.