This PHP package provides a `password_exposed` helper function, that uses the haveibeenpwned.com API to check if a password has been exposed in a data breach.
42%
Total Score
75
88
75
Packagist marks the entire package as abandoned, with no distinct replacement identified, which is a serious adoption and continuity concern. Recent releases do not remove the registry's explicit abandonment status.
Two contributors were active in the last 3 months, with the leading contributor responsible for about two-thirds of commits. The second active contributor reduces single-person dependence, though the contributor base remains small.
The repository has no security policy. For a package that checks passwords through an external breach-status service, the missing reporting and response guidance is a transparency gap.
Both workflows were analyzed without detected injection or other audit findings, but all 8 action references are unpinned. The lack of a top-level permissions block is acceptable here, while unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
nyholm/psr7 Version ^1.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
php-http/discovery Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.