The repository includes tests, a changelog, and security scanning, while the package has no install-time scripts. All eight workflow actions are unpinned, making CI supply-chain changes harder to control.
70%
Total Score
67
100
100
67
One contributor accounts for 100% of the 67 recent commits. Organization ownership provides some backing, but no second active contributor is shown to share maintenance responsibility.
The repository recorded 67 commits in the last 3 months, but all came from one active maintainer. Activity is strong, while maintenance continuity remains dependent on one person.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, though it is less severe than evidence of abandoned maintenance or unsafe release behavior.
The single workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, and it scopes permissions at job level. However, all 8 action references are unpinned, so their dependencies can change without a commit to this repository.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.