Tests, a usable README, licensing, and Composer security scanning provide a solid baseline. The small audience and unpinned workflow actions leave less evidence of sustained adoption and build reproducibility.
61%
Total Score
50
90
50
The package has 14 releases, but none in the last 12 months and its latest release was about 18 months ago, which raises maintenance risk despite its prior release activity.
The repository recorded no commits and no active maintainers in the last three months, consistent with the long release gap and reducing confidence in ongoing support.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented; the available Composer security scanning provides some compensating security hygiene.
All 9 analyzed action references are unpinned, weakening build reproducibility. This is partly offset by no untrusted checkouts, no script injection, four workflows with read-only permissions, and no audit findings.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^2.19 | — | — |
krajcik/data-builder Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.