The MIT license, matching repository, and documented package structure make its provenance clear. Its small scope keeps adoption simple, but compatibility and maintenance support are unlikely to improve.
44%
Total Score
0
64
83
Only two releases were published, with none in more than eight years. This is strong evidence that the package is no longer actively maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has zero stars and forks and only one watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of an active user or contributor community.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap for a package that has been inactive for years.
The repository is not archived, which leaves a path for future maintenance, but its last push was more than eight years ago and does not offset the inactivity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.4 | — | — |
serafim/gitter-api Version ^4.0 | — | — |
ckdarby/php-uptimerobot Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.