The MIT license, substantial README, and repository test suite provide useful transparency. The source repository is not archived and still matches the package, but these positives do not offset the release status.
18%
Total Score
50
67
50
Packagist marks the entire package as abandoned and names jeremykendall/php-domain-parser as its replacement. Package-level deprecation is a severe adoption risk because future maintenance is directed elsewhere.
The package has had no releases in more than 6 years, despite 45 releases historically. This strongly indicates that this release line is no longer maintained.
The package declares a post-install-cmd script. Install-time execution adds dependency installation complexity and supply-chain exposure, although this signal alone does not show malicious behavior.
The repository recorded no commits and no active maintainers in the last 3 months. Although it was pushed in May 2024, current activity is too low to offset the stale registry release line.
The linked repository has no security policy. That leaves vulnerability reporting and response expectations undocumented, adding a transparency gap for a package intended for application dependencies.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
voku/arrayy Version ~7.4 | — | — |
true/punycode Version ~2.1 | — | — |
voku/portable-utf8 Version ~5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.