Release documentation and repository security controls are solid, with no install-time script. The available maintenance evidence does not support relying on this release for ongoing fixes or updates.
15%
Total Score
0
64
100
Packagist marks the entire package as abandoned, with no replacement specified. This is a direct warning that new consumers should not expect supported development.
The repository had zero commits and zero active maintainers in the last 3 months, reinforcing the archived project's lack of ongoing maintenance.
The linked repository is archived, and its last push was about 10 months ago. Archiving strongly indicates that the project is no longer maintained.
Only two releases exist, with the latest released about 13 months ago and no releases in the last 12 months. The short release history and prolonged silence increase abandonment risk.
All 13 workflows were analyzed, use read-only permissions, and pin all 77 analyzed action references. The auditor also reported high-confidence template-injection findings in three security workflows; these are workflow hygiene concerns rather than a dependency-health verdict on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-mcp/server Version ^3.2 | — | — |
guzzlehttp/guzzle Version ^7.2 | — | — |
evansims/openfga-php Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.