Documentation, tests, licensing, and a matching repository make adoption straightforward. The organization-backed project is not archived, but recent maintenance has slowed and workflow dependencies are not pinned.
70%
Total Score
67
93
67
The repository had zero commits and zero active maintainers during the last three months. This is a meaningful maintenance warning, although the package still has a recent release and longer release history.
There were no new or closed issues or pull requests in the last month, despite 7 open issues and 3 open pull requests, suggesting limited recent project activity.
The project uses Composer and Robo for builds, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
No repository security policy was detected. This is a transparency gap, though it does not by itself indicate abandonment.
Both workflows were fully analyzed with no reported audit findings or untrusted checkout/script-injection sinks, but all 6 action references are unpinned and one workflow grants top-level write permissions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^8.4 | ^9.0 | ^10.0 | ^11 | ^12 | ^13 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.