The source is tiny and has no visible security policy, so long-term support and reviewability remain limited. MIT licensing, a stable release, and no install hooks reduce adoption friction.
58%
Total Score
50
75
83
The published artifact has no README, tests, or changelog. Missing tests and changelog can be normal for a small published artifact, but the absent README weakens consumer guidance for this PHP library.
The package is less than a day old, with only three releases and roughly four hours between releases. That shows active initial publishing but provides almost no evidence of sustained maintenance.
There were no commits or active maintainers in the prior three months. Because the repository itself was only pushed less than a day ago, this is weak evidence of abandonment rather than a severe maintenance failure.
The repository name does not exactly match the package name, while README mention status is unavailable. The mismatch may be ordinary naming for a related repository, so it is only a limited identity concern.
Composer is used as the build tool, but no security-scanning tool is present. The missing scanner is a modest hygiene gap for a package with no other observed build safeguards.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
niangpro/core Version self.version | — | — |
niangpro/http Version self.version | — | — |
niangpro/database Version self.version | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.