The small package is easy to inspect, with a README, tests, and a repository that mentions the package. Its single registry maintainer, zero repository popularity, and absent security tooling provide little resilience for long-term use.
32%
Total Score
33
50
61
88
Only four releases exist, with no release in the last 12 months; the latest release was in February 2019. That long release gap is a substantial maintenance concern.
There were zero commits and zero active maintainers in the last three months. Combined with the old last-pushed date, this is strong evidence of abandonment risk.
The package declares five runtime dependencies for a small API service. This is not inherently unsafe, but it increases maintenance exposure for an old release.
No declared license, license file, or repository license file was detected, leaving the legal terms for reuse unclear.
The repository is owned by an individual account rather than an organization, providing no visible organizational backing to offset the thin maintenance evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vupoint/data Version 0.0.1 | — | — |
vlucas/valitron Version ^1.2 | — | — |
guzzlehttp/guzzle Version ~5.0 | — | — |
phpoffice/phpexcel Version ^1.8 | — | — |
swiftmailer/swiftmailer Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.