The README, matching repository, and absence of install scripts provide basic transparency for consumers. The declared GPL-2.0-or-later license is broader than the detected GPL-2.0 text, and no security policy is present; maintenance activity has also stopped.
40%
Total Score
0
70
75
The latest release was nearly 7 years ago, with no releases in the last 12 months. This is strong evidence that the package is no longer actively maintained.
There were no commits or active maintainers in the last 3 months, reinforcing the long release gap and indicating little current maintenance capacity.
A license file is present, but it is detected as GPL-2.0 while the manifest declares the broader GPL-2.0-or-later; that mismatch should be clarified before adoption.
The linked repository has no security policy. This is a transparency and vulnerability-reporting gap, though it does not by itself establish that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^9.5.0 | — | — |
tecnickcom/tcpdf Version ^6.0 | — | — |
parsecsv/php-parsecsv Version ^0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.