The repository includes tests, release notes, clear documentation, and matching source files, while organization backing and security tooling add useful context. However, the package has had no registry release for over three years, has little community activity, lacks a security policy, and uses six unpinned workflow actions.
62%
Total Score
50
79
50
Only three releases were published, all clustered in March 2023, with no release in over three years. This is a meaningful maintenance concern despite the repository having been pushed more recently.
There were no new or closed issues or pull requests in the last month, while two issues and one pull request remain open. This suggests limited visible project activity.
The repository has 2 stars, 0 forks, and 1 watcher, providing very little external adoption evidence. Low popularity is supporting evidence rather than a standalone health verdict.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although the package does use a security scanning tool.
The sole workflow was fully analyzed and has no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
beberlei/assert Version ^3.3 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^1.0 | — | — |
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
php-http/discovery Version ^1.15 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.