The MIT license, repository tests, and release notes improve transparency. The workflow uses seven unpinned actions and the repository lacks a security policy, adding maintenance and build-hygiene concerns.
62%
Total Score
75
88
75
The package has existed for about 6 years with 27 releases, but only one release in the last 12 months; this indicates a slow recent cadence rather than abandonment on its own.
There were no commits and no active maintainers in the past three months, despite a recent release; this weakens evidence of ongoing maintenance capacity.
Composer is used as the build tool, but no security scanning tooling is reported, leaving a modest transparency and maintenance gap.
The repository has no security policy, so it gives consumers no documented channel or process for reporting vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all seven action references are unpinned, leaving builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ~5.0 | — | — |
graylog2/gelf-php Version ^2.0 | — | — |
kba-team/php-backtrace Version ^1.0 | — | — |
kba-team/graylog-utilities Version ^2.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.