The package is small and straightforward, with tests, a clear license, and release notes. Organization backing and a security policy add transparency, but all workflow actions are unpinned and maintenance activity has recently slowed.
68%
Total Score
75
100
88
100
The package has 34 releases over roughly seven years, but none in the last 12 months; that recent pause raises a maintenance concern.
There were no commits and no active maintainers in the last three months, which is a meaningful sign of recently limited development activity.
Composer build tooling is present, but no security scanning tool was detected; this is a modest repository hygiene gap rather than evidence of abandonment.
The sole workflow was fully analyzed with no dangerous audit findings, but all four action references are unpinned, leaving builds exposed to moving action revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aplus/debug Version ^4.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.