The organization-backed project has repository tests, release notes, a clear license, and no install-time scripts. Its small dependency set and documented package structure are reassuring, but security scanning is absent.
68%
Total Score
67
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months. This is concerning after otherwise regular releases, though the recent release and June push partly offset the abandonment risk.
There has been no issue or pull-request activity in the last month, with one open issue. This is a modest maintenance concern but not strong evidence of abandonment by itself.
Composer is used for the build, but no security scanning tools were detected. That leaves a meaningful transparency and detection gap for a dependency intended for application use.
The repository has no security policy. This weakens disclosure transparency and contributor guidance, although it is not evidence that the release is unsafe.
Both workflows were analyzed successfully and had no auditor findings, with one workflow using read-only permissions. However, all 8 action references are unpinned and one workflow has top-level write permissions, creating avoidable workflow supply-chain and privilege hygiene gaps.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
ramsey/uuid Version ^4.7 | — | — |
psr/container Version ^2.0 | — | — |
symfony/polyfill-php85 Version ^1.33 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.