A complete README, test suite, changelog, and organization-backed repository support adoption. Unpinned workflow actions and the lack of a published security policy reduce transparency and build assurance.
58%
Total Score
75
88
50
The package has 15 releases since April 2016, but its latest release was 1 year and 9 months ago and there were no releases in the last 12 months, indicating a meaningful maintenance slowdown.
The repository recorded no commits and no active maintainers in the last 3 months, which weakens evidence of ongoing maintenance even though the repository is not archived.
The repository has no published security policy and no security scanning tools were detected in the collected repository tooling, leaving vulnerability-reporting and automated security coverage unclear.
Both analyzed workflows have no top-level permissions block and all 2 of 2 action references are unpinned. The audit found no dangerous triggers, untrusted checkouts, script injection, or other severity-bearing findings, but unpinned actions weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brightnucleus/config Version >=0.4 | — | — |
brightnucleus/exceptions Version >=0.4 | — | — |
friendsofphp/proxy-manager-lts Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.