The repository is organization-backed, licensed, and free of install-time scripts. It has no tests or security scanning, while its tiny consumer README offers little integration guidance.
62%
Total Score
75
50
81
75
The package declares 66 runtime dependencies, including many platform extensions and framework components. That creates a substantial upgrade, compatibility, and transitive-maintenance burden for adopters.
The artifact includes a README, but it is only six characters long and gives consumers almost no integration guidance. The absence of tests and a changelog in the published package is normal packaging practice and is not treated as a gap.
The package has only four releases over about four years, with no releases in the last 12 months and a median interval of about 406 days. This indicates a slow maintenance cadence, though the repository was pushed more recently.
No commits or active maintainers were recorded during the last three months. This is a meaningful maintenance concern, although the repository's January 2026 push provides some counterevidence against complete abandonment.
Composer is used for builds, but no security scanning tools were detected. For a package described as an application engine with security-related components, the missing scanning coverage is a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version * | — | — |
aws/aws-sdk-php Version * | — | — |
endroid/qr-code Version * | — | — |
imagine/imagine Version * | — | — |
mongodb/mongodb Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.