The repository has tests, a usable README, organizational backing, and no install-time scripts. The declared MulanPSL-2.0 license conflicts with the repository's detected MIT license, while the workflow lacks pinned action references and the project has no security policy.
58%
Total Score
75
100
79
75
The package declares MulanPSL-2.0, but the repository license file was detected as MIT. The release is licensed, yet the mismatch creates legal ambiguity for consumers.
The package has 19 releases since April 2020, but none in the last 12 months and the latest release was in December 2023. This indicates materially reduced maintenance activity.
There were no commits and no active maintainers in the three months before collection. Combined with the stale release history, this raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. For a small component this is a transparency gap, though it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
godruoyi/php-snowflake Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.