It has a clear MIT license, tests, release notes, and no install-time scripts. A single maintainer, no recent repository activity, no security policy, and unpinned CI actions reduce resilience and transparency.
58%
Total Score
50
90
75
One registry maintainer is a thin publishing base for a small, user-owned project. The linked repository is also owned by a user rather than an organization, so there is no provided backing signal to offset the concentration.
The package has only two releases, both published within about three days, with no later release during the following roughly 10 months. That short history provides limited evidence of sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long gap since the initial release burst. No provided activity signal compensates for this pause.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. This is a hygiene and maintenance concern, not evidence of malicious behavior.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned and the workflow has no top-level permissions block. The absence of findings is reassuring, while unpinned actions remain a modest reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^10.5 || ^11 || ^12 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.