Apache-2.0 licensing and a small Composer dependency profile make the package straightforward to audit and integrate. Maintenance evidence is thin, with no commits or releases after the initial publication and no security policy.
58%
Total Score
50
100
86
75
The package has no README, tests, or changelog, but tests and changelogs normally belong in the source repository and are not expected in every published PHP module. The missing README is a minor consumer-documentation gap.
This is the only release, published 454 days ago, with no releases in the last 12 months. That limited history provides little evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, consistent with a project that has not shown recent maintenance activity.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported. This is a hygiene concern rather than evidence that the package is unsafe.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.