The repository has two high-confidence workflow findings and no commits in the last three months. It is not archived and includes tests, release notes, a matching README, and a valid MIT license.
38%
Total Score
50
71
25
Packagist marks the entire package as abandoned, which is a serious adoption concern even though a replacement with the same name is listed.
The latest registry release was over two years ago, and there were no releases in the last 12 months. This indicates a prolonged release-maintenance gap.
The audit found two high-confidence issues: a potentially spoofable actor condition in the Dependabot auto-merge workflow and an unpinned container image. All 11 action references are also unpinned, while no untrusted checkout or script-injection sink was detected.
The repository recorded zero commits and zero active maintainers in the last three months, weakening evidence of ongoing maintenance despite the repository not being archived.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, though Dependabot provides some compensating security tooling.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.4 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
symfony/http-foundation Version ^6.4|^7.0 | — | — |
eleirbag89/telegrambotphp Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.