The source includes tests, a README, release notes, a matching repository, and a valid GPL license. Its workflow is fully analyzed with no dangerous findings, but all four action references are unpinned.
20%
Total Score
50
71
Packagist marks the entire package as abandoned, with no replacement specified. Package-level abandonment is a severe dependency risk even though the individual release is not separately withdrawn.
The latest release was published in November 2020, and there were no releases in the last 12 months. This indicates prolonged release inactivity for a package intended to be adopted as a dependency.
The repository had no commits and no active maintainers in the three months before collection. The last push was in January 2023, reinforcing the lack of current maintenance.
There were no new or closed issues or pull requests in the last month, while 8 issues and 19 pull requests remained open. This suggests unresolved maintenance backlog.
All workflows were analyzed with no untrusted checkouts, script injection, or auditor findings. However, all 4 action references are unpinned, leaving avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
mezzio/mezzio Version 3.2.2 | — | — |
symfony/finder Version 5.1.8 | — | — |
ralouphie/mimey Version 2.1.0 | — | — |
intervention/image Version 2.5.1 | — | — |
laminas/laminas-log Version 2.12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.