The package is licensed, documented, actively released, and supported by an organization. Its pre-release status, single active contributor, and workflow weaknesses leave meaningful adoption risk.
64%
Total Score
67
94
100
One contributor made all 14 recent commits. Organization backing provides some handoff capacity, but no second active contributor is shown to share the maintenance load.
The repository had 14 commits in the last three months, indicating recent work, but all activity came from one active maintainer.
This release is a pre-release and 70% of recent releases are pre-releases, so consumers should expect less API stability than with a mature stable release.
All 15 analyzed action references are unpinned, and three workflows grant top-level write access; the high-confidence bot-conditions finding in the Dependabot auto-merge workflow adds further workflow hygiene risk despite no untrusted checkout or script-injection findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/schema Version ^1.3 | — | — |
kint-php/kint Version ^6.1 | — | — |
php-di/php-di Version ^7.1 | — | — |
blitz-php/cache Version ^1.4 | — | — |
guzzlehttp/psr7 Version ^2.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.