A PHP library that is fast, easy to learn and very much deprecated!
65%
Total Score
67
92
75
The artifact declares BSD-2-Clause but its license file is detected as BSD-3-Clause, creating a concrete licensing ambiguity despite the presence of a license file.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful sign of currently limited maintenance activity.
There were no new or closed issues or pull requests in the last month, with one pull request still open; this is consistent with a quiet project and reinforces the recent activity concern.
The linked repository has no security policy. This is a transparency gap, though it is less serious because the project is organization-backed and otherwise publishes tests and release notes.
The only workflow was fully analyzed with no high-confidence audit findings or dangerous triggers, but all 4 action references are unpinned, leaving build inputs less reproducible.
| Title | Versions | Severity |
|---|---|---|
CVE-2019-15521 spoon/library is vulnerable to Deserialization of Untrusted Data in versions 0.0.0 - 1.4.1. | 0.0.0 - 1.4.1 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.