Documentation, tests, changelog, and release notes make the package easier to adopt. Recent development has stopped, while the project has no security policy or scanning; pin this version and monitor for updates.
62%
Total Score
67
50
89
83
Ten runtime dependencies create meaningful transitive maintenance exposure for an integration package, though the profile is not by itself evidence of abandonment.
The package and repository are owned by the same individual account, so the ownership context is consistent but does not provide organizational continuity.
The package has 22 releases across roughly three years and released once in the last 12 months. The recent cadence is slow, but the latest release is still current rather than abandoned for years.
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful recent-maintenance gap, despite the recent release.
Composer is used for builds, but no security-scanning tooling is configured, leaving automated security coverage limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
p3k/xray Version ^1.12.0 | — | — |
lcobucci/jwt Version ^5.0 | — | — |
p3k/micropub Version ^0.0.3 | — | — |
indieauth/client Version ^1.1 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.