The MIT license, matching repository, small dependency footprint, and documented release support transparency and straightforward adoption. The lack of security scanning and a security policy leaves less assurance for a package handling CAPTCHA input.
58%
Total Score
50
100
78
67
The repository is owned by a user account rather than an organization, so there is no organizational backing shown by this signal. That is not a defect by itself, but it offers less visible continuity support than an organization-backed project.
The package has had no releases in the last 12 months, and its latest release was on March 15, 2022. This is a meaningful maintenance concern, though the 14-release history shows it was previously developed rather than abandoned from inception.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad community sustaining the package.
Composer build tooling is present, showing the project has basic ecosystem tooling. No security scanning tools are configured, leaving a transparency and maintenance gap for a package that processes user-facing CAPTCHA data.
The linked repository is not archived, although its last push was on March 15, 2022. The active status is positive, while the old push date aligns with the release-history maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mews/captcha Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.