The package is clearly licensed and documented, with a stable artifact and no install-time scripts. Its source remains unarchived and identifies the package, but it lacks a security policy and automated security scanning.
46%
Total Score
0
79
75
The latest release was in November 2019, with no releases in the following six years and ten months. This is strong evidence of abandonment risk for a library handling AWS-backed secrets.
The repository recorded zero commits and zero active maintainers during the last three months, consistent with the long release gap and indicating no current maintenance capacity.
Composer is used for the build, but no security-scanning tools are configured. The missing scanning is a modest maintenance and security-hygiene concern, not evidence that the package is malicious.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a genuine transparency gap for a package that manages secrets.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version 3.121.1 | — | — |
webmozart/path-util Version ^2.3 | — | — |
symfony/polyfill-php56 Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.