Its compact source tree and explicit Apache-2.0 license make the package easy to inspect and reuse. The three runtime dependencies add upkeep exposure, and the repository has no security policy or scanning support.
48%
Total Score
0
50
71
50
The latest release was published in July 2018, with no releases in the following eight years and only four releases overall. This indicates substantial abandonment risk despite the package reaching a stable major version.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. A stable package can need few changes, but there is no recent evidence of maintenance capacity.
The package declares three runtime dependencies, including PHP and two Techart packages. This is a manageable dependency surface, but each dependency adds maintenance exposure for an otherwise inactive project.
The artifact includes a README entry, but it is empty, and neither the package nor repository contains tests or a changelog. Missing tests and changelog are normal for published artifacts, while the empty README reduces consumer transparency slightly.
Composer is used for the build, which fits the package ecosystem, but no security-scanning tool is configured. That is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
techart/io Version >=3.0 | — | — |
techart/core Version >=3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.