Clear MIT licensing, documentation, repository tests, and organization ownership provide a solid maintenance baseline. The workflow uses two unpinned actions, and no repository security scanning is reported.
68%
Total Score
75
100
86
67
The package has existed since 2017 with seven releases, but it has had no release in the last 12 months and its median release interval is about 13 months. This indicates slow maintenance rather than abandonment by itself.
The repository recorded no commits and no active maintainers in the last 3 months. This weakens evidence of current maintenance, although the repository was pushed recently and the package has an established history.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and hygiene gap, not a severe supply-chain concern.
The linked repository has no security policy. For a small cache-provider library this is a transparency gap, though it does not indicate that the release is unsafe by itself.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but both of its two action references are unpinned. That leaves avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
willdurand/geocoder Version ^4.0|^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.