The repository includes tests, a matching source tree, and release notes for this version. Three workflow actions are unpinned and the project has no security policy or scanning, while recent commit activity is quiet.
68%
Total Score
83
100
88
67
The package has seven releases since October 2019, but none in the last 12 months and the latest registry release was in February 2023. That is a meaningful maintenance concern despite the repository having a later push.
The repository recorded zero commits and zero active maintainers in the last three months. Combined with no registry release in the last 12 months, this indicates slowing visible maintenance.
Composer is used for the build, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence of unsafe code.
The linked repository has no security policy. That weakens vulnerability-reporting transparency for a package intended to be installed as a dependency.
The single workflow was fully analyzed with no untrusted checkout or injection findings, and it has no top-level write permissions. However, all three analyzed action uses are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeception/lib-xml Version ^1.0 | — | — |
codeception/codeception Version ^5.0.8 | — | — |
codeception/lib-innerbrowser Version ^3.0 | ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.