The package is small and easy to inspect, with a clear README, MIT license, and only PHP as a runtime dependency. Its long inactivity and lack of tests or security tooling make future fixes uncertain.
54%
Total Score
25
100
81
50
The package has only two releases, both in August 2021, with no releases in the following five years. This is strong evidence of abandonment risk for a library that may need compatibility fixes.
There were no commits and no active maintainers in the last three months, consistent with a project that has seen no recent development. This materially increases the risk that defects or platform changes will remain unaddressed.
The project is backed by an individual repository owner rather than an organization, so maintenance capacity appears concentrated in a single owner. This is a modest concern alongside the lack of recent activity.
Composer build tooling is present, but no security scanning tools were detected. For a small library this is a hygiene gap, though it is less significant than the prolonged inactivity.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear. This lowers transparency but is not by itself evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.