The repository is small and has no security policy, while its Composer build has no automated security scanning. A README and exact package repository match improve transparency, but no newer maintenance evidence is present.
38%
Total Score
0
67
50
The package has had no release in nearly eight years: its latest release was October 11, 2018, with zero releases in the last 12 months. This is strong evidence of abandonment risk despite the three-release history.
The repository recorded zero commits and zero active maintainers in the last three months, and it was last pushed in October 2018. That confirms the long release gap reflects inactive source maintenance.
Neither the package nor the collected repository declares or contains a recognized license. Without licensing terms, relying on this dependency creates a material legal and transparency concern.
Composer build tooling is present, but no security scanning tools are configured. For an already inactive project, the lack of automated security checks adds to maintenance risk.
The repository has no security policy. This does not prove a vulnerability, but it leaves no documented process for reporting or handling security issues.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
popo1h/support Version * | — | — |
popo1h/phaadmin-core Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.