The package includes tests, release notes, a substantial README, and a matching MIT license. It is not deprecated or archived, but its security process is undocumented and repository activity is thin for a new integration.
68%
Total Score
75
100
89
50
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful maintenance concern even though the package is newly released.
The repository has zero stars and forks and one watcher. Popularity is only supporting evidence, but these figures provide little external validation for this new package.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security hygiene weaker than it could be.
The repository has no security policy, so there is no documented route for reporting vulnerabilities or explaining the project's security process.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all six action references are unpinned, leaving build inputs exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
feedex/feedex Version ^1.0 | — | — |
guzzlehttp/guzzle Version ^7.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.