The codebase is clearly identified, MIT-licensed, and has a matching source repository with a release for this version. Its publishing history and recent activity are too weak for a dependable dependency, and the registry marks the package abandoned in favor of a replacement.
18%
Total Score
0
63
Packagist marks the entire package as abandoned and supplies a replacement package, which is a severe adoption and maintenance risk.
The package has had no release in nearly two years and none in the last 12 months; only four releases exist, despite a short median interval earlier in its history.
The repository recorded zero commits and zero active maintainers during the last three months, providing no evidence of ongoing maintenance.
The artifact has no README, tests, or changelog, but the repository contains a README and this exact version has GitHub release notes; missing tests remain a modest transparency gap.
The repository uses Composer for builds, but no security scanning tools were detected, leaving a hygiene gap in the project’s maintenance practices.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
srvclick/scurl Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.