Documentation, licensing, release notes, and repository tests provide useful transparency, with organization backing. The single active contributor and four unpinned workflow actions are the main weaknesses.
82%
Total Score
67
94
83
One contributor made all four recent commits, creating a meaningful single-maintainer dependency risk. Organization backing provides some handoff capacity but does not remove the current concentration.
Four commits occurred in the last three months, but all were made by one active maintainer; activity is present yet narrow.
Composer build tooling is present, but no security scanning tools were detected, leaving security checks less visible than the rest of the project hygiene.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four action references are unpinned, so their versions can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
behat/behat Version ^3 | — | — |
beberlei/assert Version ^3 | — | — |
firebase/php-jwt Version ^7 | — | — |
guzzlehttp/guzzle Version ^8.0 | — | — |
jimtools/basic-auth Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.