The MIT license, repository tests, release notes, and organization ownership provide useful transparency. The small runtime dependency set and absence of unsafe workflow findings help, though all four workflow actions are unpinned.
58%
Total Score
88
100
89
100
The package has 37 releases over roughly seven years, but none in the last 12 months; this is a meaningful maintenance concern despite its historically regular release interval.
No commits or active maintainers were recorded in the last 3 months, which weakens evidence of ongoing maintenance. The repository is not archived, but that does not offset the recent inactivity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest hygiene gap rather than evidence of abandonment.
The single workflow was fully analyzed with no unsafe triggers or audit findings, but all 4 of 4 action references are unpinned, leaving avoidable build reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aplus/debug Version ^4.3 | — | — |
aplus/helpers Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.