A recent release, stable version, clear README, and documented release notes provide useful evidence of ongoing care. Maintenance is currently quiet, ownership is concentrated in one publisher, and the repository lacks security scanning; workflow references also need pinning.
61%
Total Score
50
100
94
75
Only one registry publisher is listed. The matching user-owned repository provides some continuity, but a single publisher leaves limited visible publishing redundancy.
The repository is owned by an individual account rather than an organization, so there is no visible organizational backing to offset the single-publisher and quiet-activity concerns.
The repository recorded no commits and no active maintainers in the last three months, a meaningful sign of currently quiet maintenance despite the recent registry release.
Composer is used for builds, but no security-scanning tool was detected. That is a transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version >=1.0 | — | — |
nguyenanhung/codeigniter-basic-helper Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.