The package is small and easy to inspect, with a clear README, no install-time scripts, and no workflow audit findings. Its single maintainer and absent security policy provide little evidence of ongoing support or security process.
38%
Total Score
50
58
83
This is the package's only release, published in July 2019, with no releases in the last 12 months. The long period without a new release is strong evidence of abandonment risk.
Only one registry account has publishing access. The project backing signal identifies an individual repository owner rather than an organization, so there is no shown maintainer base to compensate for this narrow publishing capacity.
The linked repository name does not match the package name and its README does not mention the package. This makes package ownership and source provenance less transparent, even though the repository contains matching-looking PHP files.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counters provide no external sign of adoption or community support.
The repository is not archived, which is a positive, but it was last pushed in August 2019 and therefore does not offset the package's prolonged inactivity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
esd/esd-core Version ~0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.