It includes a clear README, tests, and a small runtime dependency set. The repository is active and backed by an organization, but its single-contributor history and unpinned workflow actions reduce confidence.
68%
Total Score
83
100
67
One contributor made 100% of the 80 commits in the last three months. Organization backing provides some handoff capacity, but no second active contributor is visible, leaving a real continuity risk.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear.
The workflow audit completed cleanly with no untrusted checkouts, script injection, or high-confidence findings, and it scopes permissions at job level. All 8 action references are unpinned, so the workflow is exposed to avoidable action-drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/http Version ^2.0 | — | — |
ez-php/contracts Version ^2.0 | — | — |
ez-php/dataloader Version ^2.0 | — | — |
webonyx/graphql-php Version ^15.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.