The package includes tests and a usable README. Its license files conflict with the MIT manifest, creating a practical compliance question for adopters.
56%
Total Score
75
75
50
The manifest declares MIT and license files are present, but the artifact files are identified as LGPL-2.1 and GPL-3.0. That mismatch requires licensing review before adoption.
The package has 115 releases since 2017, but its latest release was over five years ago and it had no releases in the last 12 months. This is strong evidence that maintenance has stopped.
There were no commits and no active maintainers in the last three months, consistent with the release history showing more than five years without a new release. This materially raises abandonment risk.
The repository has only 2 stars and no forks, providing little external evidence of broad adoption. This is supporting caution rather than a standalone health verdict.
The repository uses Composer for builds, which fits the package ecosystem, but it has no security scanning tools. The missing scanning is a modest transparency and hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pluf/core Version 6.x | — | — |
pluf/user Version 6.x | — | — |
guzzlehttp/guzzle Version ^6.2 | — | — |
jaybizzle/crawler-detect Version 1.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.