The package has a clear MIT license, documentation, tests, and a matching source repository. Its workflows have no detected dangerous triggers or audit findings, though all 13 action references are unpinned.
60%
Total Score
50
100
94
67
The package has made 5 releases since June 2023, but none in the last 12 months and the latest release was about 22 months ago. This indicates materially slowed maintenance for a dependency.
The repository had 0 commits and 0 active maintainers in the last 3 months. That is direct evidence of currently inactive development, although it does not establish abandonment by itself.
No repository security policy was found. This is a modest transparency gap, but the package has other evidence of project structure and automated dependency scanning.
All 5 workflows were analyzed successfully with no detected dangerous triggers, sinks, or audit findings. However, all 13 action references are unpinned, which is a supply-chain hygiene weakness; the absence of top-level permissions blocks is not a concern on its own here.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phayes/geophp Version ^1.2 | — | — |
laravel/framework Version ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.