Its small codebase remains easy to inspect, and the README explains basic use. The declared MIT license conflicts with the repository's Apache-2.0 license, while absent security tooling adds a smaller transparency concern.
38%
Total Score
0
71
50
The package has had no release in nearly five years, with zero releases in the last 12 months; this is strong evidence of abandonment for a dependency.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and leaving little evidence of ongoing maintenance.
The manifest declares MIT, but the repository license file is detected as Apache-2.0. The package is licensed, but the mismatch creates avoidable legal and transparency uncertainty.
The repository has 1 star, 0 forks, and 1 watcher. Popularity is supporting evidence rather than a verdict, but these figures provide little evidence of a broad support community.
The repository has no security policy or security scanning tools. This is a secondary transparency gap, not evidence that the package is unsafe by itself.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ty-php/local-service-plugin Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.