It has a focused dependency set, Composer build metadata, tests, and an organization-owned matching repository. The project is too new to establish durable maintenance, and it lacks a security policy and automated security scanning.
68%
Total Score
75
100
80
75
This is the first release, published less than a day ago, with only one release recorded. That is expected for a new package but provides no track record for maintenance or release reliability.
The repository has no commits or active maintainers in the last 3 months. Because the repository was also created less than a day ago, this indicates limited evidence rather than established abandonment.
Composer is used for the build, which fits this PHP package, but no security-scanning tool is configured. The missing scanner is a hygiene gap rather than a severe risk on its own.
The repository has no security policy. That leaves vulnerability reporting and response expectations unclear for users of the package.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpspec/prophecy-phpunit Version 2.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.