The library is licensed, documented, and backed by repository tests. Its workflow uses seven unpinned actions, and the project has no security policy; the small dependency set and read-only job permissions provide some balance.
68%
Total Score
75
100
88
75
The package has 27 releases over more than 12 years, but none in the last 12 months and its latest registry release was in May 2023, indicating slowed maintenance.
There were no commits and no active maintainers in the three months measured, which is a concrete sign of currently inactive development despite the later repository push timestamp.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented process for reporting vulnerabilities or understanding security response expectations.
The single workflow was fully analyzed and uses read-only job permissions with no dangerous triggers or audit findings, but all seven action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
m1/env Version 2.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.