The MIT license and concise usage documentation make integration straightforward. Composer packaging is present, but there is no security policy or scanning and the project offers little operational support for current users.
40%
Total Score
38
50
67
90
The package has only one release, published more than 12 years ago, with no releases in the last 12 months. This is strong evidence of abandonment risk for a dependency targeting an evolving platform.
There were no commits and no active maintainers in the last three months, while the last known repository push was in October 2013. This is the clearest sign that maintenance has stopped.
The package has three declared runtime dependencies, including PHP, ext-curl, and phpunit/phpunit. The dependency set is small, but treating PHPUnit as a runtime dependency is unusual packaging hygiene.
Only one registry account has publish access. That is a limited publishing base, and the linked repository is user-owned rather than organization-backed, so there is little visible redundancy if the maintainer stops responding.
The registry namespace and repository owner match, supporting that the repository belongs to this package. The owner is an individual account, so there is no organization backing to compensate for the thin maintainer base.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version 3.7.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.