The package includes tests, a changelog, clear licensing, and a matching source repository. Install-time scripts, missing security-policy documentation, and unpinned workflow actions add maintenance and build-hygiene concerns.
57%
Total Score
67
100
79
50
The package runs post-install and post-update Composer scripts. These add execution during dependency installation or updates and warrant caution even though the signal does not show malicious behavior.
The package has 14 releases since November 2016, but none in the last 12 months and the latest was in February 2024. This indicates a long maintenance pause for a library dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the extended release pause. There is no provided recent activity to offset the abandonment concern.
There are no open issues or pull requests, and no issue or pull-request activity in the last month. This is neutral in isolation because zero activity can reflect either stability or inactivity, but it provides no evidence of active support.
The repository has 6 stars, 1 fork, and 2 watchers. This is limited supporting evidence for community review and does not by itself determine package health.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
remorhaz/php-json-data Version ^0.7 | — | — |
remorhaz/php-json-pointer Version ^0.7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.