The MIT license and matching repository make its provenance clear. The README supports installation, but the dependency list is unusually broad and includes tooling as runtime dependencies; no security policy adds a smaller transparency gap.
42%
Total Score
0
50
81
75
The package has had only 3 releases, with the latest on October 18, 2014 and none in the past 12 months. That long release gap is strong evidence of abandonment risk.
The repository has recorded 0 commits and 0 active maintainers in the past 3 months, with the last push in February 2015. This confirms that maintenance has been inactive for more than 11 years.
The manifest declares 10 runtime dependencies and no development dependencies, including testing, linting, static-analysis, and security-checking tools. Treating these tools as runtime dependencies increases complexity and may reflect outdated packaging.
Composer build tooling is present, but no security-scanning tools were detected in the repository. That leaves release and dependency hygiene less clearly maintained.
The linked repository has no security policy. This is a transparency gap, though it is less significant than the long-standing lack of maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpmd/phpmd Version * | — | — |
phpspec/phpspec Version ~2.0 | — | — |
phpunit/phpunit Version * | — | — |
illuminate/support Version ~4.2|~5.0 | — | — |
squizlabs/php_codesniffer Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.