MIT licensing, organization backing, tests, and a changelog provide useful transparency. The workflow has three unpinned action references and the repository lacks a security policy, so maintenance hygiene is not complete.
74%
Total Score
100
100
78
75
The package has published only five releases and none in the last two years, which raises freshness concerns; recent repository commits partly compensate but do not restore release cadence.
The repository has only three stars and two forks, indicating limited adoption evidence; popularity is supporting evidence and does not outweigh the recent activity and organization backing.
Composer build tooling is present, but no security scanning tool was detected; this is a modest project-hygiene gap rather than a standalone dependency blocker.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.2.3 is a normal, non-prerelease version, although the package remains below major version 1 and may have a less stable compatibility promise.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
webonyx/graphql-php Version ^15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.