The package includes a matching repository, MIT licensing, a README, tests, and a changelog. Its workflows use eight unpinned actions and contain a high-confidence bot-condition finding. Releases and commits have stopped for roughly two years, so maintenance risk is significant.
55%
Total Score
50
100
94
67
The latest release was in May 2024, with no releases in the following 12 months of the collected history; the earlier 43 releases show the project was once active but not recently maintained.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and raising abandonment risk.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; the presence of Dependabot provides some compensating security tooling but does not replace a policy.
All 8 analyzed action references are unpinned, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^3 || ^4 | — | — |
league/statsd Version ^2.0 | — | — |
spatie/crypto Version ^2.0 | — | — |
myclabs/php-enum Version ^1.8 | — | — |
php-amqplib/php-amqplib Version ^3.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.