It has clear licensing, tests, release notes, a stable major version, and organization backing. The repository lacks automated security scanning, while its recent workflow activity is stronger than its commit record.
68%
Total Score
83
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign that routine maintenance may be slowing.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap for a widely reused library.
All three workflows lack top-level token permissions declarations. No workflow requests top-level write access, but explicit least-privilege settings are still absent.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1 || ^2.0 | — | — |
brick/varexporter Version ^0.3.8 || ^0.4.0 || ^0.5.0 || ^0.6.0 | — | — |
laminas/laminas-stdlib Version ^3.19 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.