The source remains licensed, tested, and recently released, but its last three months show no commits and the workflow leaves all actions unpinned. Use not-empty/ulid-php-lib instead of this abandoned registry name.
38%
Total Score
75
86
50
Packagist marks the entire package as abandoned and names not-empty/ulid-php-lib as its replacement, making this release a poor dependency choice despite the active source repository.
A post-install-cmd script runs during installation, adding supply-chain exposure that should be inspected before adoption because no further script behavior is provided here.
The repository recorded zero commits and zero active maintainers in the last three months, indicating a current maintenance gap even though a recent release exists.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The workflow audit completed cleanly with no injection or high-severity findings, but all three action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.