The release notes clearly document the PHP 8.3 requirement and a serialization compatibility break. Licensing, repository tests, and readme coverage are solid, while the project’s security-process coverage is limited.
78%
Total Score
50
92
50
All two recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recently active contributor is shown to offset the concentration.
Two commits were recorded in the last three months, showing recent activity, but both came from only one active maintainer, limiting evidence of sustained maintenance capacity.
The repository uses Composer and Make, but no security-scanning tool was detected. That is a meaningful process gap, though it does not by itself indicate the release is unsafe.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations for a library intended for direct integration.
The workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or script-injection findings. However, all 9 referenced actions are unpinned, leaving workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jbzoo/utils Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.