The organization-backed project has a clear MIT license, tests, and a substantial release history. No commits in the last three months, an unmentioned package name in the repository, and completely unpinned workflow actions reduce confidence in ongoing maintenance and release hygiene.
65%
Total Score
75
88
75
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release history and recent push provide some compensation.
The repository name does not match the package name and its README does not mention the package. That weakens confidence that the linked source repository directly corresponds to this release.
Composer build tooling is present, but no security scanning tools were detected. This is a minor hygiene gap rather than evidence of abandonment.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is moderated by the project's organization backing and active release history.
The sole workflow was fully analyzed with no dangerous sinks or audit findings, but all 4 of its action references are unpinned. That leaves avoidable build-integrity exposure and lowers release hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/dbal Version ^3.3 | — | — |
keboola/retry Version ^0.5.0 | — | — |
keboola/php-utils Version ^4.1 | — | — |
google/cloud-bigquery Version ^1.23 | — | — |
keboola/php-datatypes Version >=8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.