The package is very small and gives consumers no README or license information. Its simple dependency set and matching repository reduce complexity, but there is little evidence of ongoing project activity.
35%
Total Score
50
100
67
75
Only two releases appeared on 24 November 2022, with no release in nearly four years and none in the last 12 months. This is strong evidence of abandonment risk despite the stable 1.1.0 version.
The package declares no license, includes no license file, and the repository has no license file. This leaves legal reuse unclear and is a material transparency concern.
A single registry maintainer is consistent with an independently owned package, but it leaves the project dependent on one publisher and provides little resilience if they stop maintaining it.
The complete package contains only four files: composer metadata, two source files, and a gitignore. This supports a narrow scope but provides little project documentation or evidence of engineering depth.
The published artifact has no README, while tests and a changelog are normally repository concerns and are not expected in every package artifact. The missing README still makes this small library harder to evaluate and consume.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/polyfill-mbstring Version ^1.27 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.