The artifact is licensed, documented, and includes release notes for this version. Its workflows use entirely unpinned actions and the project has a small public footprint, so updates may need extra scrutiny.
52%
Total Score
50
70
The package has had no release in over four years, despite seven releases overall; this is substantial evidence of stalled maintenance.
The repository had zero commits and zero active maintainers in the last three months, reinforcing the maintenance concern even though it was pushed in January 2025.
Version 0.3.3 is not marked as a prerelease, which supports normal consumption, but the pre-1.0 major version leaves compatibility maturity less established.
Both workflows were fully analyzed without dangerous triggers or audit findings, but all four action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
jenssegers/model Version ^1.4 | — | — |
vlucas/phpdotenv Version ^5.3 | — | — |
guzzlehttp/guzzle Version ^6.4 | — | — |
easyframework/collections Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.