Usable with caveats, but maintenance appears stalled: the latest release and repository push were in April 2024, with no commits in the last three months. The package is licensed, documented, non-deprecated, and has matching source, so it is not unfit but warrants caution before adoption.
61%
Total Score
25
100
83
83
There were zero commits and zero active maintainers in the last three months, while the repository's last push was in April 2024. This indicates a prolonged lack of visible maintenance and is the main adoption concern.
The registry namespace and repository owner are both moudarir, providing consistent ownership evidence. The owner is an individual, so the single-person backing leaves less organizational continuity than an organization-owned project.
The package has five releases since February 2023, but none in the last 12 months and the latest was in April 2024. This is a meaningful maintenance concern for a dependency, though the short early release intervals show prior activity.
The repository has only seven stars, one fork, and two watchers. This is limited supporting evidence of community use, but popularity alone does not make a small, otherwise coherent package unhealthy.
Composer is used for builds, but no security scanning tools are configured. That weakens automated maintenance coverage, although it is a gap rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version ^2.72 | — | — |
firebase/php-jwt Version ^6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.