The release has a clear license, tests, release notes, and an active organizational owner. Maintenance has paused for three months, while workflow automation has a high-confidence bot-condition issue and five unpinned actions.
58%
Total Score
67
100
94
75
Both workflows were analyzed, but all five action references are unpinned, and a high-confidence bot-conditions finding reports spoofable actor context in the auto-merge workflow. One workflow also grants top-level write access, increasing automation risk.
The package has 11 releases over more than eight years, but only one release in the last 12 months and a median interval of about 264 days indicate a slow maintenance cadence.
No commits and no active maintainers were recorded in the last three months, a concrete sign that maintenance has stalled recently.
There are no open issues and five open pull requests, but none were created or merged in the last month, offering little evidence of active issue handling.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap, not evidence of malicious behavior.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^10.5.0 | — | — |
sebastian/comparator Version ^5.0.1 | — | — |
diablomedia/zendframework1-db Version ^1.0.5 | — | — |
diablomedia/zendframework1-dom Version ^1.0.5 | — | — |
diablomedia/zendframework1-filter Version ^1.0.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.