Risky to adopt: this package has had no release or repository activity for roughly nine years, with no tests or README for consumers. It is not deprecated or archived, but the tiny, inactive project and unclear repository match make ongoing support uncertain.
38%
Total Score
25
100
61
83
There has been only one release, published roughly nine years ago, with no releases in the last 12 months. That strongly limits evidence of ongoing maintenance, although the package is not formally deprecated.
There were no commits and no active maintainers in the last three months, consistent with a project that has been inactive since its initial release.
The package has no README, which is a real consumer-transparency gap for a helper library. The absence of tests and a changelog in the published artifact is normal packaging practice, while a GitHub release exists for this version.
The package and repository are owned by the same individual account, which provides direct ownership alignment but no organizational backing or broader support evidence.
The repository name does not match the package name, and the collected data does not show the package being mentioned in its README. That raises uncertainty about whether this repository directly backs the package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
duosecurity/duo_php Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.