The repository includes broad tests, release notes, and a matching MIT license. Its small maintainer base and no recent commits leave less evidence of ongoing support, while workflow references are unpinned.
68%
Total Score
50
94
75
Only one account has registry publishing access. Because the repository is user-owned rather than organization-backed, this leaves limited visible publishing continuity if that maintainer becomes unavailable.
The repository had zero commits and zero active maintainers in the last three months. Although a recent release provides some counterevidence, this still weakens confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, not evidence that the package is unsafe.
The repository has no published security policy, leaving vulnerability reporting and response expectations unspecified.
The single workflow was fully analyzed with no audit findings or untrusted-trigger sinks, but all three action references are unpinned, allowing dependency changes without a fixed revision.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.0 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
php-http/discovery Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.