The package has clear licensing, organization backing, and a matching seven-file source tree. Its last release and recent repository activity are over three years old, while documentation and security safeguards are thin.
60%
Total Score
75
79
83
The artifact includes a README and a GitHub release for this version, but the README is only 19 characters and the project has no tests or changelog. Missing tests and changelog are normal packaging practice, while the very limited consumer documentation is a minor concern.
The latest release was published over three years ago, with no releases in the last 12 months; the five-release history shows an established but inactive package.
The repository had zero commits and zero active maintainers in the last three months, reinforcing the prolonged maintenance gap.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest repository-hygiene gap.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a package that has been inactive for years.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.