Its small artifact and lack of install-time scripts reduce packaging complexity. The single-maintainer project has no recent release activity, and licensing is unclear; avoid making it a default dependency.
38%
Total Score
50
60
75
No license is declared, no license file is present in the package, and no repository license could be checked. This creates a real legal and adoption risk.
The package has 19 releases since November 2018, but its latest release was over three years ago and it had no releases in the last 12 months. That is strong evidence of inactivity.
Only one registry maintainer is listed, leaving little visible publishing capacity or backup if maintenance stops. This compounds the long release gap.
The artifact contains only composer.json and fcv.phar, which is consistent with a small compiled command-line distribution but provides little consumer-facing context.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.