The package is intentionally minimal, with a focused dependency profile, clear README, and a release note for this version. Its long release gap and license mismatch reduce confidence in ongoing maintenance and licensing clarity.
68%
Total Score
50
100
79
88
The artifact and repository contain a BSD-3-Clause license file, but the manifest declares the package as proprietary. The conflicting declarations reduce licensing clarity despite the available license text.
The package has five releases since June 2022, but none in the last 12 months and the latest registry release was in November 2024. This is a meaningful maintenance concern for a package tracking PHP versions and polyfills.
There were no commits and no active maintainers in the three months measured. The recent repository push is a compensating sign, but the observed commit inactivity still lowers confidence in active maintenance.
Composer is used as the build tool, which fits the package ecosystem, but no security-scanning tool was detected. The missing scanner is a modest transparency gap rather than a severe dependency risk.
The repository has no security policy. For this small package that is a minor transparency gap, but it provides no documented channel or process for reporting issues.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.