Recent releases, tests, and two active contributors show ongoing work. All 11 workflow actions are unpinned, and no security policy is present.
39%
Total Score
100
75
50
Packagist marks the entire package as abandoned and provides no replacement, a serious adoption and continuity risk even though recent releases exist.
The repository name does not match the package name and its README does not mention the package, creating uncertainty that the linked repository directly represents this release.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
Both workflows were fully analyzed with no dangerous triggers or audit findings, but all 11 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
bjeavons/zxcvbn-php Version * | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.