Long release history, tests, a changelog, and a security policy provide useful maintenance context. The repository has no commits in the last three months, all five workflow actions are unpinned, and the repository does not identify the package by name.
72%
Total Score
83
100
94
75
Composer post-install and post-update scripts run during dependency operations, adding execution complexity for consumers. No accompanying evidence shows these scripts are unsafe, so this is a limited supply-chain hygiene concern.
The repository recorded zero commits and zero active maintainers in the last three months. This is a concrete sign of quiet current maintenance, partly offset by the recent package release and repository push.
The repository name does not match the package name and its README does not mention the package. Although the organization backing is consistent, the missing direct identification leaves some uncertainty that this repository is the package's exact source.
All four workflows were analyzed successfully with no detected findings, dangerous triggers, untrusted checkouts, or script injections. However, all five analyzed action references are unpinned, which weakens build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.15 | — | — |
ray/aop Version ^2.12 | — | — |
aura/router Version ^3.2 | — | — |
bear/sunday Version ^1.8 | — | — |
nyholm/psr7 Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.