The package includes a substantial test suite, changelog, and a repository that clearly matches the package. Composer security scanning and scoped workflow permissions help, but all eight Actions references are unpinned and recent commits come from one contributor.
78%
Total Score
83
100
100
67
All 82 recent commits came from one contributor, creating a real continuity risk. The organization-owned repository provides some ability to hand maintenance off, so this is a caution rather than a severe abandonment signal.
The repository has no published security policy, which weakens the project's disclosure transparency, though active maintenance and security scanning partly offset the concern.
The single workflow was fully analyzed, uses job-level permissions, and has no untrusted checkout, injection, or high-confidence audit findings. However, all eight action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/mail Version ^2.0 | — | — |
ez-php/push Version ^2.0 | — | — |
ez-php/queue Version ^2.0 | — | — |
ez-php/broadcast Version ^2.0 | — | — |
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.