The package is clearly licensed and includes a README, tests, and release notes. Its workflow is fully audited, but all three actions are unpinned and no security policy is present.
42%
Total Score
70
50
There has been only one release, published about 6 years ago, with no releases in the last 12 months. This is strong evidence of abandonment for a dependency.
The package defines a post-update command, which runs package-manager lifecycle code during updates. This adds some supply-chain exposure, although only one script is reported.
The repository is not archived, which is a positive counterpoint, but its last push was about 6 years ago and reinforces the stale release history.
The repository has no security policy. For an application starter intended to be deployed, this weakens vulnerability-reporting and maintenance transparency.
The single workflow was fully analyzed with no audit findings or dangerous triggers, but all 3 of its action references are unpinned. That is a reproducibility and update-integrity gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeigniter4/framework Version ^4.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.