The package is easy to inspect and has straightforward Composer integration. Its last release and repository activity date to 2016, while the repository has no security policy or scanning, making continued maintenance a substantial concern.
40%
Total Score
0
75
75
The package has had no release in nearly ten years, despite being about ten years old. This is strong evidence of abandonment for a library that may need compatibility and security maintenance.
The repository recorded no commits or active maintainers in the last three months, and its last push was in 2016. The long-running inactivity is not offset by any newer maintenance signal.
The repository has only 2 stars, 1 fork, and no watchers. Popularity is not decisive, but this provides little evidence of a broader community that could sustain the package.
Composer is used for builds, which supports reproducible packaging, but no security scanning tools were detected. This is a modest transparency and maintenance gap.
The repository has no security policy. For an API integration library, this weakens vulnerability-reporting transparency, although it is secondary to the much older maintenance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rypsx/ipapi Version ^1.0 | — | — |
nesbot/carbon Version ^1.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.