PHP Client for Elasticsearch
40%
Total Score
0
75
75
The package has 93 releases, but its latest release was over five years ago and it has had no releases in the last 12 months. That strongly indicates the release line is no longer maintained.
The repository recorded zero commits and zero active maintainers in the last three months, matching the long release gap and providing no evidence of ongoing maintenance.
The artifact and repository contain license files, but the artifact identifies both Apache-2.0 and LGPL-2.1 while the manifest declares only Apache-2.0. The files provide transparency, but the declaration mismatch warrants checking before adoption.
The linked repository has no security policy, reducing transparency about how vulnerabilities are reported and handled. The repository's other documentation does not compensate for this specific gap.
All three workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, or audit findings, but all six referenced actions are unpinned. This is a supply-chain hygiene gap without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
ezimuel/ringphp Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.