It has a clear BSD license, a substantial README, repository tests, and organization backing. Unpinned workflow actions and the lack of a security policy add maintenance and release-hygiene concerns.
57%
Total Score
50
81
50
The package has 16 releases since October 2014, but none in the 12 months before collection and the latest release was over four years ago. This is a substantial maintenance concern despite the long history.
There were no commits and no active maintainers in the three months before collection. Combined with the old latest registry release, this points to materially reduced maintenance capacity.
A post-autoload-dump lifecycle script runs during installation. This adds execution surface for consumers, but the signal alone does not show that the script is unsafe or unusually risky.
The repository uses Make and Composer, but no security-scanning tooling was detected. This is a hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. That weakens vulnerability-reporting transparency for a package intended to be integrated into applications.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
icanboogie/event Version ^4.0 | — | — |
icanboogie/errors Version ^2.0 | — | — |
icanboogie/operation Version ^5.0 | — | — |
icanboogie/icanboogie Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.