The package is small and lacks automated security scanning and a security policy. Its MIT license, README, and matching repository improve transparency, but the release remains difficult to trust for long-term maintenance.
40%
Total Score
50
100
78
83
This is the package's only release, published about 4 years 8 months ago, with no releases in the last 12 months. That is strong evidence of abandonment risk for a dependency.
The repository shows no new or closed issues or pull requests in the last month, and no open work. Combined with the old release, this provides no evidence of ongoing maintenance.
The repository has 0 stars and 0 forks, with only 1 watcher. Popularity is not required for health, but these counters provide little supporting evidence of active use or review.
Composer is used for builds, but no security scanning tools are present. That reduces supply-chain transparency, though it is a hygiene gap rather than evidence of a harmful release.
The repository has no security policy. This weakens the project's disclosure and maintenance transparency, although the absence does not by itself show that the package is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
postalservice14/php-actuator Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.