Its packaging is clean and the dependency boundary is explicit. Treat long-term support as unproven until more releases establish a track record.
64%
Total Score
75
100
88
83
This is the first release, published today, so there is no track record for release continuity or maintenance yet. That is a genuine maturity gap, though it does not by itself indicate abandonment.
There were no commits or active maintainers in the past three months, but the package is only one day old, so this currently shows limited history rather than clear abandonment.
The repository uses Composer, which fits the package ecosystem, but no security-scanning tool was detected. That is a modest transparency and assurance gap.
No security policy was found in the repository, leaving vulnerability-reporting expectations unspecified. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.