Security documentation and scanning are absent, and the project has seen no commits for more than five years. The MIT license, useful README, and lack of deprecation provide some reassurance, but maintenance risk remains high.
40%
Total Score
0
100
64
83
This is the package's only release, published more than five years ago, with no releases in the last 12 months. That strongly indicates an unmaintained project.
There were no commits or active maintainers in the last three months, providing direct evidence that the project is not currently maintained.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap for a library handling API credentials.
The repository is not archived, which avoids a severe abandonment indicator, but its last push was more than five years ago and is consistent with the stale release history.
The repository has no security policy, leaving users without a documented vulnerability-reporting process. The small, inactive project provides no compensating security process.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.