The artifact is substantial and has no install-time scripts, while the repository matches the package. A single maintainer and no security policy leave limited operational transparency.
38%
Total Score
33
50
75
The indicator found neither a declared license nor a recognized license file. Without clear reuse terms, adopting this package creates a concrete legal and maintenance concern.
There has been only one release, about 2 years and 10 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a package consumers must maintain around.
The repository had zero commits and zero active maintainers in the last 3 months, consistent with the package having received no follow-up work since its initial release.
The artifact has no README, tests, or changelog, and the repository also reports no tests or changelog. The missing consumer documentation is a meaningful gap for a PHP library, although the absence of tests and changelog alone is not decisive.
The package and repository are owned by the same individual account, with no organization backing shown. That is consistent ownership but provides limited evidence of maintenance capacity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.