Testing, documentation, and a small dependency surface support adoption. Maintenance is concentrated in one contributor, while every analyzed workflow action is unpinned and the repository has no security policy.
68%
Total Score
67
100
94
67
The package has published 85 releases in 199 days, with a median interval of about 3.5 hours. This shows active work but an unusually rapid cadence that can make release selection harder.
One contributor made 100% of the 80 recent commits. Although the repository is organization-owned, no second active contributor is shown to provide practical handoff capacity.
The repository recorded 80 commits in the last three months, showing strong recent activity. However, all of those commits came from one active maintainer, so the activity does not demonstrate broad maintenance capacity.
The repository has no published security policy. That weakens transparency around vulnerability reporting and response, even though dependency scanning is present.
The single workflow was fully analyzed with no high-confidence audit findings or untrusted code paths, and it scopes permissions at job level. All 11 action references are unpinned, leaving workflow dependencies exposed to moving targets.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.