A short README, release notes for this version, and a declared BSD-2-Clause license improve transparency. Composer-based publishing and a repository that matches the package help, but the missing security policy leaves a smaller documentation gap.
46%
Total Score
0
75
50
The latest release was in May 2022, and there were no releases in the last 12 months despite the package being about 4 years and 8 months old. This is strong evidence of abandonment risk, although the package is not deprecated.
The repository had 0 commits and 0 active maintainers in the last 3 months, confirming that current maintenance is absent rather than merely having a slow release cadence.
The repository uses Composer build tooling, which supports reproducible package conventions, but no security scanning tools were detected. This provides limited positive maturity evidence without compensating for the maintenance gap.
The linked repository has no security policy, leaving contributors and consumers without a documented route for reporting vulnerabilities. This is a modest transparency gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ppadevs/ddd Version ^2.2 | — | — |
ppadevs/file Version ^2.2 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
ppadevs/soap-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.