The license declaration and detected file text do not match, and no security policy is provided. Tests, documentation, and a long release history offset those transparency gaps.
68%
Total Score
50
100
86
67
The package declares GPL-2.0-or-later, while the artifact license file was detected as GPL-2.0; the presence of license files in both package and repository is otherwise positive.
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful recent-maintenance concern despite the recent release and push evidence.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented; this is a transparency gap rather than evidence of unsafe code.
The assessed version is 8.0.0, but the collected latest version is 7.0.3; this inconsistency reduces confidence that registry and release metadata are aligned.
Both workflows were analyzed completely with no dangerous triggers, untrusted checkouts, or audit findings, but all 11 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
smottt/wideimage Version ~1.1.1 | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.