The package includes tests, a usable README, a stable release, and only two runtime dependencies. Recent repository activity is absent, and the declared GPL license differs from MIT and BSD-3-Clause files found in the artifact; no security tooling or policy is present.
68%
Total Score
83
100
83
50
The manifest declares GPL-2.0-or-later, while artifact license files are recognized as MIT and BSD-3-Clause. Because the detected licenses are not covered by the declaration, this creates a real licensing transparency concern.
The repository recorded zero commits and zero active maintainers during the last three months. This is a meaningful maintenance concern, despite the recent registry release history.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, so these low counts modestly limit external validation but do not determine health.
Composer build tooling is present, but no security scanning tools were detected. That leaves a modest gap in automated security hygiene rather than indicating abandonment.
The repository has no security policy. This reduces transparency about vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/fast-route Version 2.0.0-beta1 | — | — |
mevdschee/php-crud-api Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.