Clear documentation, tests, and organization backing improve confidence in the package's basic quality. The remaining publication and workflow hygiene gaps add avoidable adoption risk.
43%
Total Score
50
100
69
100
The package has had no releases in roughly five years, despite four releases within its initial month. That long publication gap is strong evidence of abandonment risk.
The repository recorded no commits and no active maintainers in the last three months, consistent with the last push being roughly five years ago. This substantially weakens confidence in ongoing maintenance.
No declared license or license file was found in the package or repository. Without licensing terms, legal reuse and dependency adoption are materially harder.
Composer build tooling is present, but no security scanning tools were detected. This is a limited hygiene gap rather than evidence that the package is unsafe.
The repository is not archived, which preserves a path for maintenance, but its last push was roughly five years ago. The inactivity is already reflected more strongly by release and commit signals.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.