The tiny repository has no commits in the last three months, and its README does not identify this package. It has a license, a usable README, and two recent releases, but workflow references are unpinned.
61%
Total Score
75
86
50
There were zero commits and zero active maintainers in the last three months. The recent release and repository push show some activity, but the absence of ongoing development is a meaningful maintenance concern.
The repository name does not match the package name and its README does not mention the package. Although name differences can occur in related projects, this combination weakens confidence that the repository is the intended source.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe package.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for a dependency with two runtime dependencies.
The single workflow was fully analyzed with no injection or high-severity findings, but both of its two action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.