The package is clearly licensed, documented, tested in the repository, and backed by an organization. Its small, read-only provider has limited recent activity, while the workflow uses two unpinned actions and the repository has no security policy.
68%
Total Score
75
100
83
67
The package has six releases since August 2017, but none in the last 12 months and a median release interval of about 585 days. This fits a small provider with infrequent releases, but leaves limited evidence of current maintenance.
There were zero commits and zero active maintainers in the last three months. Although the repository was pushed in November 2025, the recent inactivity limits confidence in ongoing maintenance.
The repository has two stars and one fork, indicating limited adoption. Popularity is supporting evidence only, so this does not outweigh the clearer maintenance signals.
Composer build tooling is present, but no security scanning tools are reported. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For a small read-only adapter this is a limited gap, but it reduces clarity about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
willdurand/geocoder Version ^4.0|^5.0 | — | — |
geocoder-php/common-http Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.