The package brings 66 runtime dependencies and runs post-install and post-update commands, increasing integration and upgrade burden. It has a license, tests, a README, organizational backing, and an unarchived matching repository, but registry releases stopped nearly two years ago and no commits were recorded in the last three months.
58%
Total Score
83
50
88
67
The package declares 66 runtime dependencies and no dev dependencies, including many framework components and platform extensions. That broad runtime footprint increases compatibility, deployment, and upgrade burden.
Post-install and post-update commands run during Composer operations, which adds execution and upgrade complexity for consumers. No provided signal compensates for that operational burden.
The latest registry release was nearly two years before collection, and there were no releases in the preceding 12 months. Earlier releases were relatively close together, but the current pause raises maintenance concern.
No commits and no active maintainers were recorded in the last three months. The repository's recent push date is a compensating sign of availability, but the measured development pause still lowers confidence in active maintenance.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a hygiene gap rather than evidence that the package is unsafe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
google/auth Version * | — | — |
aws/aws-sdk-php Version * | — | — |
endroid/qr-code Version * | — | — |
imagine/imagine Version * | — | — |
mongodb/mongodb Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.