The package has a clear repository match, a real license file, and only PHP as a runtime dependency. The declared MIT license conflicts with the detected Apache-2.0 file, and the repository has no security policy.
44%
Total Score
0
100
64
75
This is the only release since November 2024, with no releases in the last 12 months; that strongly suggests an immature or abandoned dependency.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
The release includes a license file, so it is not unlicensed, but the manifest declares MIT while the detected file says Apache-2.0; that mismatch requires legal clarification before adoption.
A short README helps installation, but the artifact and repository contain no tests or changelog. Missing tests are a meaningful maintenance gap for a large library, while the missing changelog is less important for a one-release package.
Composer is used for the build, which fits the package ecosystem, but no security scanning tooling is present and there is no other provided evidence of automated security checks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.