The package has a long release history, six releases in the last year, tests, and a clear license. Repository security documentation is absent, and all 11 workflow actions are unpinned.
68%
Total Score
50
100
89
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance warning, although the package had six registry releases in the last year.
The repository has zero stars, one fork, and one watcher. This indicates limited adoption evidence, but popularity is supporting evidence and does not outweigh the package's release and testing record.
Composer is used as a build tool, which fits the package ecosystem, but no security scanning tools were detected. The missing scanning is a modest repository hygiene gap.
The repository has no security policy. That weakens vulnerability-reporting transparency, but it is not evidence that the package is unsafe by itself.
Both workflows were fully analyzed with no untrusted checkouts, injection findings, or excessive permissions. However, all 11 action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
elgg/elgg Version ~7.0.0 | — | — |
composer/installers Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.