It is MIT-licensed, matches its repository, and includes tests, but documentation is only a five-character README and no security policy is published. Its small dependency set and lack of install scripts reduce exposure, yet the project shows little evidence of current care.
42%
Total Score
67
100
79
75
The artifact includes tests, which is a small positive, but its README is only 5 characters and there is no changelog. The missing changelog is normal packaging practice; the extremely limited README weakens consumer transparency.
The last release was over five years ago, with no releases in the preceding 12 months. That is substantial evidence of abandonment despite a history of 12 releases.
The repository recorded zero commits and zero active maintainers in the last three months, indicating that current development has stopped or effectively stalled.
There are no open issues or pull requests and no recent issue or pull-request activity. This is consistent with a dormant project, though it does not alone establish abandonment.
Composer is used for the build, but no security-scanning tooling is present. That is a modest maintenance and transparency gap for a package intended for application integration.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
pluf/core Version 6.x | — | — |
pluf/tenant Version 6.x | — | — |
mustache/mustache Version 2.12.x | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.