MIT licensing, matching source, and release notes improve transparency. The workflow is audited but uses three unpinned actions, leaving a modest reproducibility gap.
15%
Total Score
50
67
50
Packagist marks the entire package as abandoned and names codeception/module-laravel as its replacement. This is a direct adoption risk, not merely a warning about one release.
The latest release was nearly six years ago, with no releases in the last 12 months and only three releases overall. This strongly indicates the package is no longer actively maintained.
The repository recorded no commits and no active maintainers in the measured three-month period. Together with the old registry release, this supports a substantial abandonment concern.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, though it is secondary to the package's abandonment and deprecation status.
The single workflow was fully analyzed with no reported injection or high-confidence security findings. However, all three referenced actions are unpinned, creating a modest supply-chain reproducibility weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeception/codeception Version ^4.0 | — | — |
codeception/lib-innerbrowser Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.