Tests, licensing, and consumer documentation are in place. The evidence supports a cautious dependency choice, with limited recent project activity and workflow hygiene reducing confidence.
60%
Total Score
50
88
50
The package has had no releases in the last 12 months, and its latest release was about 13 months ago. Its 10 releases since 2019 show an established project, but not current momentum.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, indicating no recent maintenance activity. The repository is not archived and was pushed with the assessed release, which partly offsets but does not remove the concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This matters for a package that handles bank-account connectivity, although it does not by itself indicate abandonment.
The sole workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but both of its 2 action references are unpinned. That leaves avoidable build-integrity risk while the rest of the workflow audit is clean.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 | — | — |
illuminate/config Version >=8.0 | — | — |
abiturma/php-fints Version ^2.0 | — | — |
illuminate/console Version >=8.0 | — | — |
illuminate/support Version >=8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.