The repository has tests, a clear MIT license, and a useful readme, with no install scripts or deprecation. Maintenance is concentrated in one contributor, and all 10 workflow actions are unpinned.
78%
Total Score
67
100
67
One contributor made all recent commits, creating a meaningful single-person continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Six commits were made in the last three months, but all recent activity came from one active maintainer, limiting demonstrated maintenance depth.
The repository has no published security policy, which weakens vulnerability-reporting transparency for a library handling authentication, tokens, and database-related functionality.
The workflow uses read-only permissions and has no detected injection or high-severity findings, but all 10 analyzed action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^4.3 | — | — |
symfony/cache Version ^8.0 | — | — |
moneyphp/money Version ^4.8 | — | — |
symfony/mailer Version ^8.0 | — | — |
cakephp/chronos Version ^3.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.