12%
Total Score
50
67
50
Packagist marks the entire package as abandoned, with no replacement identified; this is a direct warning against taking a new dependency on it.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the abandonment concern.
The linked repository is archived despite being pushed recently, so normal issue handling and future maintenance should not be expected.
No security policy is present in the linked repository, leaving vulnerability-reporting expectations unclear; this is a secondary transparency gap.
The single workflow was fully audited with no reported findings and no broad write permissions, but both analyzed action references are unpinned, creating a modest reproducibility and workflow-supply-chain weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
adhocore/cli Version ^0.9.0 | — | — |
symfony/yaml Version 6.* | — | — |
beberlei/assert Version ^3.3 | — | — |
firebase/php-jwt Version ^v6.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.