Clear documentation, tests, licensing, and a matching source repository make adoption easier. The package has a small dependency surface, but its maintenance appears dormant and the repository lacks a security policy or scanning tools.
61%
Total Score
50
100
88
83
The package and repository are owned by the same individual account, providing consistent ownership context but no organizational backing to offset the thin maintenance base.
The latest release was in October 2018, with no releases in the last 12 months. The package has five releases over its lifetime, so this is a meaningful maintenance concern rather than a brief pause.
There were no commits and no active maintainers in the last three months. Combined with the old latest release, this indicates dormant maintenance and raises abandonment risk.
Composer is used for the build, but no security scanning tools were found. That is a transparency and maintenance gap, though it is not severe enough to make the release unfit by itself.
The repository has no security policy. This weakens vulnerability-reporting transparency for a package that handles external HTTP requests, but it is not evidence of a vulnerability.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bcosca/fatfree Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.