The repository has had no commits in the last three months, despite recent releases and pull-request activity. It has clear licensing, tests in the repository, release notes, organizational backing, and a security policy.
78%
Total Score
83
100
94
100
There were zero commits and zero active maintainers in the last three months, a meaningful maintenance warning. Recent releases and pull-request activity provide some compensating evidence but do not remove the gap.
The repository uses Composer build tooling, but no security scanning tools were detected; the missing scanning is a modest transparency gap for a dependency project.
All three workflows were analyzed without audit findings or untrusted checkouts. Two of three action references are unpinned and one workflow has top-level write permissions, creating limited workflow hygiene risk without a dangerous trigger or sink.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
psr/simple-cache Version ^2.0 || ^3.0 | — | — |
webmozart/assert Version ^1.11 || ^2.1.6 | — | — |
laminas/laminas-stdlib Version ^3.20 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.