Its small dependency surface and matching source repository make the code relatively easy to inspect. Maintenance appears effectively abandoned: the last release and repository push were in February 2016, with no recent commits or active maintainers; security documentation and scanning are also absent.
35%
Total Score
25
100
75
75
The package has had only four releases, all concentrated in February 2016, and none in the last 12 months. This is strong evidence of abandonment for a dependency consumers may need maintained over time.
There were zero commits and zero active maintainers in the last three months, consistent with the repository's last push in February 2016. The repository is not archived, but it shows no recent maintenance capacity.
There has been no issue or pull request activity in the last month. This is supporting evidence of dormancy rather than a severe concern by itself.
Composer is used as the build tool, which is appropriate for this PHP package, but no security scanning tools are present. That leaves a modest transparency and maintenance gap.
The repository has no security policy. For a small, dormant library this reduces the clarity of vulnerability reporting and response expectations.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.