Usable with caveats: it has clear ownership, licensing, tests, release notes, and a steady release history. However, the repository has had no commits or active maintainers in the last three months, and the project lacks a security policy and explicit workflow token permissions.
72%
Total Score
75
100
86
67
There were no commits and no active maintainers in the last three months. Although the release history is healthy, this recent inactivity lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap without making the package unfit to use.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow has no top-level token permissions declaration. No write permissions were detected, but explicitly limiting permissions would provide stronger workflow hygiene.
Version v0.2.2 is not a prerelease, but the package remains below major version 1, so compatibility expectations are less mature.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.