It includes an MIT license, tests, a useful README, and a stable v1.0.0 release. The project has no commits in the past year, and all seven workflow actions are unpinned; the organization backing and read-only workflow permissions partly offset this.
60%
Total Score
75
88
50
This is a one-release package first published about a year ago, with no releases in the last 12 months. That leaves limited evidence of sustained maintenance, though the project is still relatively young.
The repository recorded zero commits and zero active maintainers in the past three months, consistent with a project that has seen no recent development. Its recent initial release provides some context but does not demonstrate ongoing maintenance.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The package's tests and otherwise straightforward repository structure provide some compensating maturity evidence, but not a reporting process.
Both workflows use read-only permissions and the audit found no untrusted checkouts, script injection, or other findings, which is positive. However, all seven action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2 || ^3 | — | — |
psr/http-message Version ^1.0 | — | — |
knplabs/gaufrette Version ^0.11.1 | — | — |
ondrej-vrto/php-filename-sanitize Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.