This is a generally healthy, actively maintained PHP package with a stable 1.4.0 release, six releases over roughly nine months, a non-archived repository, recent commit and release activity, clear licensing, and a small runtime dependency profile. The repository provides tests and substantial development tooling even though tests are not included in the artifact. The main concerns are that all 13 commits in the last three months came from one contributor, the repository has no security policy or security-scanning tool, and most workflows lack explicit top-level permissions; these reduce resilience and operational transparency but do not outweigh the evidence of ongoing maintenance and coherent package/repository ownership.
78%
Total Score
90
100
94
80
All 13 recent commits came from one contributor, creating a genuine continuity risk; organization ownership partly compensates because maintenance can potentially be handed off within the organization.
Composer build tooling is present, but no security-scanning tool was detected, leaving a security-process hygiene gap.
The repository has no SECURITY.md or other detected security policy, reducing vulnerability-reporting transparency.
Four workflows lack top-level permissions and one release workflow grants top-level write access, so CI permission hygiene is weaker than desirable even though no dangerous workflow behavior was detected.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.