Clear licensing, tests, documentation, and a small dependency surface support maintenance quality. Pin version 1.0.8 only if you can accept owning compatibility and security review for this largely abandoned library.
38%
Total Score
50
100
78
83
The package has nine releases, but all activity ended on May 11, 2021 and there have been no releases in roughly five years. That is strong evidence of abandonment for a library dependency.
There were zero commits and zero active maintainers in the last three months, consistent with maintenance having stopped for years.
One registry maintainer account is listed. Because the source repository is organization-owned, this is not by itself a major concern, but it provides limited visible publishing redundancy.
The repository has zero stars, forks, and watchers. Popularity is not decisive, but these counts provide no supporting evidence of community adoption or external review.
Composer build tooling is present, but no security-scanning tooling was detected. The missing scanning practice is a modest transparency and maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
piggly/php-payload Version ^1.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.