Tests, a changelog, and Composer security scanning provide useful maintenance evidence. Workflow references are not pinned, and the project has limited independent contributor coverage despite organizational ownership.
73%
Total Score
67
100
100
67
One contributor made 100% of the 69 recent commits. Organizational ownership provides some handoff capacity, but independent contributor coverage remains thin.
The repository recorded 69 commits in three months, demonstrating strong recent activity, although all commits came from one active maintainer.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The workflow is fully analyzable and uses job-level permissions, with no dangerous audit findings, but all 8 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/http Version ^2.0 | — | — |
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.