It has a matching repository, an Apache-2.0 license, repository tests, and organization ownership. Its tiny adoption footprint and lack of security scanning provide little additional confidence for a long-lived dependency.
38%
Total Score
50
69
50
This is the package's only release, published about nine years ago, with no releases in the last 12 months. That strongly suggests abandonment risk despite the package not being deprecated.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive for years. This is the strongest maintenance concern.
The repository has one star, zero forks, and one watcher, indicating very limited adoption. Popularity is supporting evidence rather than a verdict, but it adds to the uncertainty around this inactive package.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, not a severe risk on its own.
The repository has no security policy. For a package containing account, organization, and session models, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-platform/config Version ~0.1 | — | — |
php-platform/persist Version ~0.1 | — | — |
php-platform/session Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.