The README is brief, and the project has no security policy or automated workflow evidence. Its stable version and matching repository provide some transparency, but there is little evidence of ongoing support for a dependency last released about eight years ago.
40%
Total Score
71
50
No license is declared, detected, or included in the package or repository. This is a material transparency and adoption problem with no provided evidence compensating for it.
The package has only two releases, both from 2018, with no releases in about eight years. That sharply increases abandonment risk despite the stable 1.0.1 version.
The repository has zero stars, forks, and watchers, offering no supporting evidence of community adoption or review. Popularity is only supporting evidence, so this reinforces rather than determines the concern.
Composer is used as the build tool, which fits the package ecosystem, but no security scanning tools are present. This is a minor hygiene gap alongside the broader maintenance concerns.
The repository has no security policy. For a small package this is a modest transparency gap, though it is less serious than the lack of recent maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
noking50/user Version ^1.0 | — | — |
noking50/dblog Version ^1.0 | — | — |
noking50/sitemap Version ^1.0 | — | — |
noking50/fileupload Version ^1.0 | — | — |
noking50/pagination Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.