The package is clearly licensed, tested, and tied to a matching organization-owned repository with release notes. Its lack of a security policy and security scanning leaves important transparency gaps.
58%
Total Score
67
100
81
75
Only two releases were published, both in February 2016, with no registry release in about 10 years. The repository was pushed in 2024, which provides some compensating evidence but does not show a current release cadence.
The repository had zero commits and zero active maintainers in the last three months. Its 2024 push shows it is not wholly abandoned, but current maintenance capacity is weak.
There were no new or closed issues or pull requests in the last month, while 16 issues and 11 pull requests remain open. This suggests limited recent project responsiveness.
Composer build tooling is present, but no security scanning tools are configured. That leaves dependency and source-risk checks less transparent.
The repository has no security policy, so users have no documented process for reporting vulnerabilities or understanding security response expectations.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mustangostang/spyc Version ^0.5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.