Clear documentation, tests, licensing, and release notes improve confidence. The organization-owned repository and matching package source provide useful continuity, but ongoing activity remains thin.
67%
Total Score
67
93
75
The package has existed for about 5 years with 20 releases, but only one release appeared in the last 12 months, indicating a slower recent cadence.
One contributor made all commits in the last 3 months. Organization ownership offers some handoff capacity, but no second active contributor is shown.
Only one commit was recorded in the last 3 months, showing limited recent maintenance activity despite the recent release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Both workflows were analyzed without high-confidence audit findings or untrusted triggers, but all 6 action references are unpinned, weakening build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version ^10.0 | — | — |
stomp-php/stomp-php Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.