This is a healthy, mature release with nearly eight years of history, 60 releases, 17 releases in the last 12 months, and a recent stable release. The linked organization-owned repository is active, unarchived, package-matched, tested, documented, and backed by substantial recent commit and pull-request activity. The main reservations are that one contributor made 81.25% of recent commits, repository security scanning was not detected, and two workflows lack top-level permission declarations; these are meaningful hygiene considerations but are moderated by active secondary contributors, organization backing, a security policy, and the absence of detected dangerous workflow patterns.
91%
Total Score
90
100
94
90
The top contributor made 81.25% of recent commits, creating concentration risk. The two additional contributors remain active, and organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
Composer build tooling is present, but no repository security-scanning tool was detected. The missing scanning automation is a hygiene gap, though other security signals provide partial compensation.
Two workflows lack top-level permission declarations, which weakens least-privilege clarity. However, no workflow has top-level write permissions, and the analyzed workflows include read-only or job-level permission controls, limiting the concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^5.10.7 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
carnage/php-graphql-client Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.