The package is well documented, tested, licensed, and backed by an organization. Maintenance has gone quiet since the latest release, and the workflows use unpinned actions with inherited secrets.
65%
Total Score
75
100
88
88
The package has existed since 2015 with 19 releases, but it has had no releases in the last 12 months, which lowers confidence in current maintenance.
There were no commits and no active maintainers in the prior three months, reinforcing the concern raised by the absence of releases in the last year.
There are no open issues or pull requests, but there was also no issue or pull-request activity in the last month; this provides little evidence of ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest repository hygiene gap.
All three workflows were analyzed with no untrusted checkout or script-injection findings, but all 11 action references are unpinned and a high-confidence medium-severity secrets-inherit finding affects the stale workflow.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ml/json-ld Version ^1.0.4 | — | — |
easyrdf/easyrdf Version ^1 | — | — |
guzzlehttp/guzzle Version ^6.5.8 || ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.