The package has repository tests, a matching source project, an MIT license, and a published release note. All four workflow actions are unpinned, security scanning is absent, and reported recent commit activity is zero.
70%
Total Score
75
100
86
100
The package has 105 releases since July 2021, but only 2 releases in the last 12 months, indicating a slower current cadence without abandonment by itself.
The repository reports zero commits and zero active maintainers during the last 3 months. This weakens evidence of ongoing maintenance, although the separate recent push and release history provide some counterweight.
Composer build tooling is present, but no security scanning tools were detected. That is a maintenance and transparency gap rather than evidence that the package is unsafe.
The sole workflow was fully analyzed with no audit findings or untrusted checkouts, but all 4 action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aplus/debug Version ^4.3 | — | — |
aplus/helpers Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.