The package has clear licensing, documentation, release notes, and organization ownership. Its narrow PHP dependency profile and active pull requests help, while the missing security policy and weak workflow pinning add maintenance risk.
73%
Total Score
88
100
93
75
All three recent commits came from one contributor, concentrating current maintenance capacity and increasing continuity risk.
The project uses Composer build tooling, but no security scanning tools were detected. For a native PHP extension, that leaves a useful security-maintenance gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
All nine workflows were analyzed with no untrusted checkout, script-injection, or audit findings, but 34 of 47 action references are unpinned and three workflows grant top-level write permissions. With no untrusted trigger sink, this is workflow hygiene risk rather than a severe supply-chain issue.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.