The package has a clear MIT license, a usable README, and no install-time scripts. Its repository lacks security scanning and a security policy, leaving vulnerability response and future maintenance uncertain.
44%
Total Score
25
79
75
The package has had no release in more than eight years, despite five releases clustered on April 30, 2018. This is strong evidence of abandonment risk, although the stable release and small scope partly limit the impact.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. No newer activity is provided to offset the maintenance concern.
Only one registry maintainer is listed, which leaves little visible publishing capacity. The linked repository is also owned by the same individual, so there is no shown organizational backing to compensate.
Composer is used as the build tool, but no security scanning tools are present. For a small, old PHP integration package, this is a hygiene gap rather than evidence that the release is unsafe by itself.
The repository has no security policy, reducing transparency about vulnerability reporting and response. This is a meaningful but secondary concern beside the prolonged inactivity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.