The project has a clear README, a matching source repository, an MIT license, and no install-time scripts. However, its release and commit activity stopped in August 2024, while the repository shows no recent contributors and no security policy. Its very small public footprint adds adoption risk.
42%
Total Score
33
50
72
75
The package has had 7 releases, but none in the last 12 months and its latest release was about 2 years ago. The short burst of releases in August 2024 does not demonstrate continuing maintenance.
The repository had 0 commits and 0 active maintainers in the last 3 months. Combined with the last push being about 2 years ago, this is strong evidence of abandonment risk.
The package declares 13 runtime dependencies and no development dependencies. This is a meaningful integration surface, though the signal alone does not show unresolved or excessive dependency risk.
The repository is owned by an individual user rather than an organization. That is not inherently unhealthy, but it indicates limited visible institutional backing when recent activity is already absent.
There are no open issues or pull requests and no activity in the last month. A clean issue tracker is not proof of maintenance, and here it does not offset the lack of commits.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webman/captcha Version ^1.0 | — | — |
webman/console Version ^1.3 | — | — |
monolog/monolog Version ^2.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
illuminate/events Version ^11.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.