There is no automated security scanning or security policy, though the MIT license, tests, and matching repository improve transparency. Organization backing and an active, unarchived repository reduce the concern but do not offset the thin maintenance evidence.
45%
Total Score
50
72
67
The package has made only one release, about 7 years and 5 months ago, with none in the last 12 months. This is strong evidence of an effectively inactive release line.
There were no commits or active maintainers in the last 3 months, and the repository's last push was about 5 years and 6 months ago. This is the clearest maintenance and abandonment risk.
Composer post-install and post-update scripts add install-time behavior that consumers must trust and review, creating a modest supply-chain hygiene concern.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet project, but does not independently prove abandonment.
The repository has 0 stars, 1 fork, and 0 watchers. Low adoption is supporting evidence of limited maturity, though popularity alone is not decisive.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
restapix/resta Version dev-master | — | — |
zendframework/zend-crypt Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.