phpdot/path appears usable and reasonably transparent for a young package: it is not deprecated or archived, has a clear MIT license, a matching public repository, Composer-based build metadata, and repository tests that compensate for the absence of packaged tests. However, it is only 53 days old, remains on an unstable 0.x major version, has just three releases, and all three recent commits come from one contributor. The organization-owned repository provides some maintenance continuity, but the lack of a security policy and security scanning leaves notable hygiene gaps. Overall, this is a plausible dependency for projects comfortable with an early-stage package, but it warrants monitoring and should not be treated as mature infrastructure.
72%
Total Score
70
100
78
90
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpdot/config Version ^0.3 | — | — |
phpdot/package Version ^0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.