Usable with caveats: it has a long release history, a current stable release, active organizational backing, tests, and release notes. However, the repository shows no commits or issue activity in the last three months and lacks a security policy, so maintenance responsiveness should be verified before adopting it broadly.
68%
Total Score
67
100
94
67
There were zero commits and zero active maintainers during the last three months. Although a recent release and repository push provide some compensating evidence, the lack of current development activity raises maintenance risk.
The repository has 41 open issues and four open pull requests, but recorded no new or closed issues and no merged pull requests in the last month. This suggests limited visible responsiveness.
Composer is used for builds, but no security-scanning tool was detected. This is a transparency and maintenance gap, though the workflow analysis found no direct dangerous behavior.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
All four analyzed workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
codeception/stub Version ^4.0 | — | — |
codeception/lib-web Version ^1.0.1 || ^2 | — | — |
codeception/codeception Version ^5.0.8 | — | — |
php-webdriver/webdriver Version ^1.14.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.