Repository tests, release notes, stable versioning, and organizational backing provide useful support. Unpinned workflow actions and the lack of a security policy leave preventable maintenance and supply-chain hygiene gaps.
58%
Total Score
75
100
88
75
The latest registry release was in June 2021, with no releases in the last 12 months; this is a substantial maintenance warning, although the repository was pushed more recently.
There were no commits or active maintainers in the three months before collection, which weakens evidence of current maintenance capacity.
The project uses Composer but has no detected security-scanning tools; the missing scanning coverage is a modest repository hygiene concern.
No security policy was found in the repository, leaving vulnerability reporting expectations undocumented.
The single workflow was fully analyzed with no audit findings or untrusted checkouts, but all four action references are unpinned, weakening build reproducibility and tamper resistance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravie/codex Version ^5.1 | — | — |
php-http/multipart-stream-builder Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.