A small codebase and minimal dependency footprint keep adoption simple. The long inactivity and lack of tests, documentation, and security policy leave too little evidence for a dependable dependency.
44%
Total Score
50
100
75
75
The package includes a GitHub release for this version, but it has no README, tests, or changelog. Missing tests and changelog are normal in published artifacts, while the missing README is a documentation gap for a library.
Only two releases exist, both in April 2023, with no releases in the last 12 months; the package has been unchanged for about 3 years and 5 months.
The repository recorded no commits and no active maintainers in the last 3 months, consistent with the long release gap and raising abandonment concerns.
Composer is used for the build, which is appropriate, but no security scanning tools are present. This is a modest transparency and maintenance gap rather than a standalone severe risk.
The linked repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mpm/validation Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.