Usable with caveats: the package is actively releasing, correctly linked to an organization-backed repository, and has a clear license and source tree. Its short 43-day history, only two recent commits from one contributor, and absence of security policy or scanning leave maintenance depth unproven.
72%
Total Score
75
100
94
90
One contributor made all 2 commits in the last 3 months, creating a concentrated maintenance dependency. Organization ownership offers some handoff potential, but no second active contributor is shown.
Only 2 commits were made in the last 3 months, all during a package history that is just 43 days old. The recent release activity is encouraging, but the limited commit record leaves maintenance capacity only partly demonstrated.
Composer build tooling is present, but no security scanning tools are configured. For a package exposing many device and application APIs, this is a meaningful transparency gap.
The repository has no security policy. That makes vulnerability reporting and response expectations less clear for adopters.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
chillerlan/php-qrcode Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.