It has a clear license, a useful README, tests, and a recent release with documented fixes. The small public footprint and absent security policy reduce transparency, while the recent release history and organization backing limit abandonment concern.
78%
Total Score
75
100
89
80
There were no commits and no active maintainers in the three months before collection. Recent releases compensate partly, but the lack of current development activity remains a maintenance concern.
There are no open issues or pull requests and no recent issue or pull-request activity. This may reflect a quiet, small project rather than abandonment, so it is only a mild concern.
Six stars and three forks indicate a small user base. This lowers independent evidence of maturity but is supporting evidence only and does not outweigh the project's other health signals.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning coverage is a transparency gap for a package handling signed URLs.
The repository has no security policy. For a component intended for secure URL signing, that leaves vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
yiisoft/yii2 Version ^2 | — | — |
psr/clock-implementation Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.