The package has a very small footprint and no security policy or scanning, which limits transparency. Its source is identifiable and not archived, but the release remains an alpha with no follow-up releases or recent development.
35%
Total Score
50
50
63
75
The package declares two runtime dependencies, including phpspec/phpspec, with no development dependencies. This is a small dependency set, but the apparent test framework as a runtime dependency is unusual and adds avoidable dependency surface.
The manifest declares a proprietary license, with no recognized license text or license file in the package or repository. This is a significant adoption and transparency concern for an open-source dependency.
The repository is owned by an individual account rather than an organization, so the single registry maintainer is not explained by organizational backing. This leaves limited visible maintenance capacity.
Only one release exists, published about 10 years ago, with no releases in the last 12 months. This strongly indicates abandonment risk for a dependency.
There have been no commits and no active maintainers in the last three months, consistent with a project that has been inactive for years. This is the strongest maintenance concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jasny/dotkey Version v1.0.0 | — | — |
phpspec/phpspec Version 2.4.0-alpha1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.