The source repository is substantial and the release is a stable major version. Seven runtime dependencies add upkeep burden, while the declared proprietary license conflicts with the repository's BSD-3-Clause license and no security policy is published.
44%
Total Score
0
50
70
88
The package is two years old but has only three releases, all clustered within about 12 hours, with no releases in the last 12 months. That provides little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the last push being about two years ago. This is strong abandonment evidence.
The package declares seven runtime dependencies, including payment, spreadsheet, and geolocation libraries. That breadth increases maintenance and compatibility demands for an inactive package.
The manifest declares a proprietary license, while the repository license file is recognized as BSD-3-Clause. The release is not clearly aligned on licensing, creating a real adoption concern.
The linked repository has no security policy. This weakens vulnerability-reporting transparency, though it is less serious than the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bluem/tree Version ^3.2 | — | — |
ramsey/uuid Version ^4.7 | — | — |
cocur/slugify Version ^4.6 | — | — |
geoip2/geoip2 Version ^3.0 | — | — |
stripe/stripe-php Version ^15.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.