The package is small, clearly licensed, and tied to a matching organization repository with a stable release note. Its lack of tests and security scanning leaves less evidence for long-term maintenance, despite a clean dependency and install profile.
62%
Total Score
67
100
78
83
The package has 7 releases since March 2021, but none in more than 2 years; the long period without a release lowers confidence in ongoing maintenance.
There were no commits and no active maintainers in the last 3 months, which is direct evidence that current maintenance activity has stopped.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a quiet project, but does not independently prove abandonment.
The repository has no stars, forks, or watchers. This is weak supporting evidence and does not by itself make a small, otherwise coherent package unsafe to adopt.
Composer build tooling is present, but no security scanning tool is configured; this is a modest transparency and maintenance-hygiene gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpzlc/phpzlc Version 3.* | — | — |
gregwar/captcha Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.