Its tests, MIT license, organization backing, and established release history support adoption. Keep the broad workflow secret access, fully unpinned actions, and absent security policy in mind.
68%
Total Score
75
100
94
50
There were no commits and no active maintainers in the last three months, a meaningful maintenance slowdown despite the release history and the repository's recent push.
Composer build tooling is present, but no security-scanning tool was detected; this is a maintenance and transparency gap rather than evidence of unsafe behavior by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear for a library handling storage and API integrations.
The sole workflow passes the audit without untrusted checkouts or script injection, but all 6 actions are unpinned and it exposes the entire secrets context, creating avoidable workflow hygiene and credential-sprawl risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
monolog/monolog Version ^2.3 | — | — |
symfony/process Version ^6.0 | — | — |
keboola/php-temp Version ^2.0 | — | — |
keboola/storage-api-client Version ^15.2 | — | — |
keboola/notification-api-php-client Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.