The package is licensed and the repository matches it, with tests and a clear README. CI has an unpinned container image and no security policy, so future maintenance and build reproducibility deserve attention.
60%
Total Score
50
92
67
The latest release was about 16 months ago, with no releases in the last 12 months. That slows confidence in ongoing maintenance, although the package has six releases and a regular earlier cadence.
The repository recorded no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, though the repository is not archived and the latest release was published around the same time.
The repository has no security policy. For a small testing helper this is a transparency gap rather than evidence of abandonment, but it leaves vulnerability reporting expectations unclear.
The workflow audit completed successfully and found no dangerous triggers or untrusted checkouts, but all six action references are unpinned and a high-confidence finding reports an unpinned container image. This weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^8.5 || ^9.0 || ^10.0 || ^11.0 || ^12.0 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
jfcherng/php-diff Version ^6.14 | — | — |
codeception/codeception Version 4.*||5.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.