The source is licensed, tested, documented, and backed by an unarchived organization repository. Its Composer install script fits a project template. All four workflow actions are unpinned and the repository has no security policy.
60%
Total Score
75
80
75
The latest release was published about 8 years ago, with no releases in the last 12 months. This is a substantial freshness and abandonment concern, even though the linked repository was pushed more recently.
There were no commits or active maintainers in the last 3 months, which weakens the evidence of ongoing maintenance despite the repository's more recent push date.
The repository has no security policy. This is a transparency and reporting gap, but it is moderated by the package's clear license, documentation, tests, and repository backing.
The workflow audit completed fully with no untrusted checkouts, script injection, or high-confidence findings. However, all 4 action references are unpinned, leaving avoidable build reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
khs1994/curl Version ~18.06.0 | — | — |
pimple/pimple Version ~3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.