It has a clear README, MIT licensing, repository tests, release notes, and a small dependency set. Unpinned workflow actions and no security policy reduce maintenance transparency.
58%
Total Score
50
100
90
67
The package has had no registry release in more than four years, after 11 releases since February 2019. This is a meaningful maintenance concern, though the stable 1.8.0 release and repository evidence provide some continuity.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with a project that has been inactive since 2022. This raises abandonment risk for future fixes.
The linked repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled. This is a modest concern for a small, focused package rather than a severe dependency risk.
The sole workflow was fully analyzed with no dangerous sinks or audit findings, but all 3 action references are unpinned. That leaves avoidable workflow supply-chain hygiene risk without making the package unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
adbario/php-dot-notation Version ^3.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.