The package includes a substantial README, extensive tests, and release notes, with no install-time scripts or deprecation notice. Its solo maintainer base and lack of security scanning reduce long-term resilience.
62%
Total Score
67
100
86
83
Only one registry account has publish access. This is a resilience concern for an individually owned project because publication and maintenance depend on one person.
The package has 39 releases since February 2016, but none in the last 12 months and its latest registry release was in December 2020. This is meaningful maintenance risk despite the earlier regular release cadence.
There were no commits and no active maintainers in the measured three-month period. Combined with the old registry release, this supports a caution about stalled maintenance.
The repository uses Composer, but no security scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
No security policy was found in the linked repository. This weakens the project's process transparency, although it does not by itself show abandonment.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nesbot/carbon Version >=1.20 | — | — |
guzzlehttp/guzzle Version >=3.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.