It includes a clear README, changelog, matching EUPL-1.2 licensing, and no install-time scripts. The source is small, has no security policy, and its only workflow uses an unpinned action. Use openeuropa/code-review instead.
20%
Total Score
0
75
75
Packagist marks the entire package abandoned and provides openeuropa/code-review as its replacement, making this release unsuitable for a new dependency.
The repository recorded zero commits and zero active maintainers over the last 3 months, reinforcing the package's abandonment risk.
The repository name does not match the package name and its README does not mention this package, creating uncertainty about the linkage even though it is organization-owned.
No security policy was found in the linked repository, leaving vulnerability-reporting expectations undocumented.
The single workflow was fully analyzed with no dangerous findings, but its only action use is unpinned, so the workflow has a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpro/grumphp-shim Version 2.17.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.