Clear licensing, tests, security scanning, and a security policy support adoption. The package omits a README and uses four unpinned workflow actions, leaving some provenance and consumer-documentation gaps.
82%
Total Score
67
100
93
75
post-install-cmd and post-update-cmd scripts run during dependency operations, which adds supply-chain exposure compared with a package without install-time behavior. No provided signal shows those scripts are unsafe, so this is a limited caution rather than a severe finding.
The package and repository are owned by the same named individual rather than an organization. This is coherent ownership, but it provides less institutional handoff capacity than organization backing.
The package is young at 58 days and has shipped 23 releases, with a median interval of about 3 hours. That rapid cadence warrants some maturity caution, although the consistent release activity is also evidence that the project is being maintained.
Two contributors were active, and the second contributor made 32.5% of recent commits, but the leading contributor still made 67.5%. This leaves some concentration risk in a user-owned project.
All workflows were analyzed successfully, use read-only permissions, and contain no detected injection or high-confidence audit findings. However, all 4 of 4 action references are unpinned, so workflow reproducibility and supply-chain hygiene are weaker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danog/php-rtc-mixin Version ^1.1.6 || ^2.0 | — | — |
phpseclib/phpseclib Version ^4.0 | — | — |
danog/php-rtc-exception Version ^1.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.