Clear documentation, tests, licensing, and stable release practices reduce integration risk. The organization backs the project, though workflow image pinning and the absent security policy deserve maintenance attention.
78%
Total Score
90
100
94
75
Only one commit was recorded in the last 3 months, which is thin repository activity, but it is partly compensated by 22 registry releases in the last year and a push on the assessment date.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency gap rather than evidence of abandonment, given the active release history.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. The gap matters for a backend component but is not severe enough to outweigh the maintenance evidence.
The single workflow was fully analyzed with no untrusted checkouts or script-injection findings, but all 5 action references are unpinned and a high-confidence unpinned-container-image finding was reported. This is a workflow reproducibility and supply-chain hygiene concern, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zozlak/auth Version ^3.1 | — | — |
zozlak/logging Version ^1 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
zozlak/http-accept Version >=0.1.0 <1 | — | — |
acdh-oeaw/arche-lib Version ^7.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.