Usable with caveats: the package is small, clearly packaged, licensed, and not deprecated or archived. However, it has had no release or repository activity for about 3 years and 5 months, with no security policy or scanning, so verify compatibility before adopting it.
55%
Total Score
50
100
81
83
The repository is owned by an individual user rather than an organization, so the project has limited visible institutional backing. That is a modest resilience concern, especially alongside one registry maintainer and long inactivity.
Only two releases were published, with the latest released about 3 years and 5 months ago and none in the past 12 months. This indicates a largely inactive project, although the package may be intentionally stable.
The repository recorded zero commits and zero active maintainers during the past three months, consistent with the last push being about 3 years and 5 months ago. This is the strongest evidence that ongoing maintenance should not be assumed.
Composer is used for the build, which is appropriate for a PHP package, but no security-scanning tools are configured. That weakens maintenance transparency without making the package unfit by itself.
The linked repository is not archived, so it remains possible for maintainers to update it. Its last push was about 3 years and 5 months ago, which still reinforces the maintenance concern shown by release history.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vkcom/kphp-polyfills Version ^1.0 | — | — |
nyan02/kphp_oauth2_client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.