The project has a clear README, repository tests, an MIT license, and organization backing. It has only one published release, no commits in the last 3 months, and all seven workflow actions are unpinned; no security policy or scanning is present.
60%
Total Score
83
100
88
50
This is a 276-day-old package with only one release and no releases in the last 12 months beyond the initial version, leaving limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months, which is a meaningful sign of currently stalled development for a newly released package.
Composer build tooling is present, but no security scanning tools were detected. This weakens repository hygiene without independently indicating abandonment.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The workflow audit completed fully and found read-only permissions with no injection or high-severity findings. However, all 7 of 7 action references are unpinned, leaving avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.1 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
crustum/plugin-manifest Version ^1.0 | — | — |
caseyamcl/guzzle_retry_middleware Version ^2.12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.