The repository includes a substantial test suite, clear licensing, and a README that explains integration. Its release history is very short, the repository has no security policy, and all 10 workflow actions are unpinned, limiting confidence in long-term maintenance and build hygiene.
68%
Total Score
100
81
75
The package is only about 10 months old and has three releases, all published within roughly two days in November 2025; this shows initial activity but little evidence of sustained maintenance.
The repository has zero stars and forks and one watcher, providing little external evidence of adoption or community validation; popularity is supporting evidence rather than a standalone health verdict.
Composer is used for builds, but no security scanning tools are configured. The missing scanning coverage is a modest transparency and maintenance concern.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The single workflow was fully analyzed and has no dangerous triggers, untrusted checkouts, or audit findings, but all 10 action references are unpinned. That weakens build reproducibility and supply-chain hygiene without making the release unfit on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.52 | — | — |
nesbot/carbon Version ^3.8.4 | — | — |
symfony/process Version ^6.0||^7.0 | — | — |
dragonmantank/cron-expression Version ^3.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.