The package includes tests, a clear README, few runtime dependencies, and active recent releases. It lacks a security policy, while organization backing and Composer audit provide some operational support.
72%
Total Score
67
100
100
75
One contributor made 100% of the 77 recent commits. This creates a real continuity risk, although the repository is owned by an organization that can potentially provide handoff capacity.
The repository recorded 77 commits in the last three months, showing strong activity, but all were made by one active maintainer.
No repository security policy was found, leaving vulnerability reporting expectations and response guidance undocumented.
The single workflow was fully analyzed, uses job-level permissions, and has no untrusted checkout or script-injection findings. However, all 8 referenced actions are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ez-php/contracts Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.