The project has a stable v2 release, recent registry activity, and a matching organization-backed repository. Zero recent commits and missing licensing leave maintenance and legal transparency uncertain, while the build workflows need tighter pinning.
63%
Total Score
75
92
50
No license is declared, detected, or included in the package or repository. This creates a real legal-transparency concern for adoption.
post-install-cmd and post-update-cmd scripts run during Composer operations, adding execution surface during installation and updates. No provided signal shows these scripts are unsafe, so this is a hygiene concern rather than a severe finding.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. The recent registry release partly offsets this, but the lack of observed source activity raises maintenance risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the repository does use GitGuardian scanning.
Both workflows were fully analyzed with no dangerous sinks or audit findings, but all 6 action references are unpinned. That leaves CI exposed to moving action revisions and is a moderate hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
tracy/tracy Version ^2.7 | — | — |
drago-ex/simple Version ^2.0 | — | — |
drago-ex/project-docker Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.