Unpinned workflow actions and no security scanning weaken release hygiene. The MIT license, repository tests, release notes, and matching unarchived source repository provide meaningful support for adoption.
67%
Total Score
75
81
50
The package has 10 releases over about 2 years and only one release in the last 12 months, indicating a materially slower recent cadence despite its earlier release activity.
The repository recorded zero commits and zero active maintainers during the last three months, which weakens evidence of ongoing maintenance after the release.
The repository has only 1 star, 0 forks, and 1 watcher. This is limited supporting evidence, but low popularity alone does not make a small maintained package unsafe.
The project uses Composer and Make, but no security scanning tool was detected. That is a modest release-hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.1 || ^2 || ^3 | — | — |
psr/container Version ^1.1 || ^2 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
webonyx/graphql-php Version ^15.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.