The package is a tiny Composer artifact with a declared runtime dependency and no tests; that is understandable for a small utility. Its lack of a license, eight years without a release or commit, and repository/name mismatch make adoption a liability.
30%
Total Score
25
38
The package has only two releases, both from April 2018, and none in the past 12 months. This long period without releases is strong evidence of abandonment risk.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with the release history showing no activity since 2018. This materially raises maintenance risk.
No license is declared, detected, or supplied in the package or repository. That leaves the legal terms for reuse unclear and is a meaningful transparency gap.
The registry lists one maintainer. A single maintainer is not inherently unhealthy for a small package, but it provides little redundancy when combined with the absence of recent release and commit activity.
A README file is present, but it contains no content, and the source repository has neither tests nor a changelog. The empty README reduces consumer transparency, while missing tests and changelog are expected packaging gaps here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
clickalicious/memcached.php Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.