The project includes tests, a changelog, release notes, and a clear README. Its workflow avoids the analyzed dangerous patterns, but the lone publisher and missing top-level token permissions leave less operational depth.
58%
Total Score
50
100
78
90
The repository had no commits and no active maintainers in the last three months. Combined with the old last push, this is strong evidence of stalled maintenance.
Only one account has registry publishing access. That is a thin operational base and increases continuity risk, although access records do not establish who actively maintains the project.
The repository is owned by an individual account rather than an organization. This is not inherently unhealthy, but it offers less visible institutional continuity to offset the thin maintainer base.
The latest release was published roughly three years ago, with no releases in the last 12 months. That materially raises maintenance risk despite three total releases since 2022.
The repository has one star, no forks, and one watcher. Limited adoption provides little supporting evidence, but popularity alone is not a health verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^8.0 || ^9.0 || ^10.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.