Adapter for official PHP OpenSearch client
65%
Total Score
caution
Usable with caveats: no commits or releases since May 2023.
The package has five releases and a short early median interval, but it has had no registry release in more than three years, indicating a real maintenance concern.
The repository recorded no commits and no active maintainers during the last three months of the assessment period, consistent with the long release gap and raising abandonment risk.
The repository has no SECURITY.md policy and no security scanning tools, leaving security reporting and automated checks less transparent than they could be.
All 10 workflow action references are unpinned, and the auditor found low-confidence cache-poisoning patterns in three workflows. No untrusted checkout, injection sink, or broad top-level write permission was found, so this is workflow hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
friendsofcat/opensearch-client Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.