Tests, a changelog, active releases, and organization backing improve confidence. Pin the workflow actions and broaden contribution beyond the single recent contributor before making it foundational.
69%
Total Score
83
100
94
67
The package has published 88 releases in 199 days, with a median interval of about 4 hours. This demonstrates active maintenance but also suggests unusually rapid release churn.
All 83 recent commits came from one contributor, leaving no demonstrated recent handoff capacity. Organization backing partially reduces the risk but does not remove the concentration concern.
No repository security policy was found. This is a transparency gap for a framework, although the repository does use dependency security scanning.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-confidence findings, and job-level permissions are used. However, all 11 analyzed action references are unpinned, leaving avoidable supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/http Version ^2.0 | — | — |
ez-php/i18n Version ^2.0 | — | — |
ez-php/dotenv Version ^2.0 | — | — |
ez-php/console Version ^2.0 | — | — |
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.