Testing and release hygiene are visible, and the package is clearly licensed. Use ebics-api/ebics-client-php instead, since this package is marked abandoned despite recent project activity.
63%
Total Score
83
83
50
The registry marks the entire package as abandoned and names ebics-api/ebics-client-php as its replacement. Recent releases and active repository work reduce abandonment concern but do not remove the migration risk.
All 12 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
The repository has no security policy, leaving no documented reporting path for a library handling banking integrations. Other repository and workflow evidence does not compensate for that transparency gap.
Both workflows were analyzed with no high-confidence audit findings or unsafe-trigger sinks, but all 7 action references are unpinned and one workflow grants top-level write access. These are actionable supply-chain hygiene weaknesses, not standalone severe risks.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.