The repository includes tests, the package is clearly licensed, and it was pushed recently. All four workflow action references are unpinned, and no security policy or recent three-month commit activity is visible.
68%
Total Score
75
100
88
50
There were no commits and no active maintainers in the last three months, indicating a recent pause in source maintenance and increasing abandonment risk.
The repository uses Composer, but no security-scanning tools were detected. This is a transparency and hygiene gap, not evidence that the package is unsafe.
No repository security policy was found, reducing the project's documented disclosure transparency, though this alone does not indicate that maintenance has stopped.
Version 0.19.5 is not a stable major release, but it is not marked as a prerelease and recent releases contain no prerelease versions.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
boson-php/runtime Version ^0.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.