Tests and a clear GPL license support adoption. The workflow uses four unpinned actions, while the repository has neither a security policy nor security scanning. Recent releases help offset the lack of commits in the last three months.
67%
Total Score
50
94
67
The repository recorded no commits and no active maintainers during the last three months. The recent registry release partly offsets this, but the short-term lack of source activity raises maintenance risk.
Composer build tooling is present, but no security-scanning tools were detected. That leaves automated vulnerability checking less visible than it could be.
The repository has no security policy. This is a transparency gap for a library, though it is not evidence of a security defect by itself.
The single workflow was fully analyzed with no high-confidence audit findings or untrusted checkout and injection issues. However, all 4 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rmccue/requests Version ^2.0 | — | — |
symfony/process Version ^5.3 | — | — |
datagutten/tools Version ^1.11 | — | — |
symfony/polyfill-php80 Version ^1.23 | — | — |
datagutten/audio-metadata Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.