Clear documentation, tests, and matching MIT licensing support adoption. The single publisher and absent security policy leave limited resilience if maintenance problems emerge.
45%
Total Score
25
75
50
The latest release was published in June 2020, with no releases in the following six years and a total of only six releases. This is strong evidence of abandonment for a library dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, but it shows no recent maintenance.
The package runs post-install and post-update Composer scripts, increasing installation complexity and the amount of package behavior that must be trusted. No other provided signal shows these scripts are unsafe.
Only one registry account can publish releases, leaving a thin publishing base. The linked repository is owned by the same individual, so there is no visible organizational backing to compensate.
The repository has no security policy, leaving no documented process for reporting or handling security issues. This compounds the risk of an inactive project, although it is not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.4 | — | — |
facebook/webdriver Version ^1.7 | — | — |
shimabox/url-status Version ^1.0 | — | — |
shimabox/selenium-downloader Version ~0.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.