A clear license, release notes, and complete project layout improve transparency. Issue and commit activity show the project is being maintained, though automated security safeguards are limited.
85%
Total Score
88
94
75
One contributor made 90% of the last three months' commits, creating concentration risk; two additional contributors remained active, partly reducing the concern.
Composer is used for builds, but no security scanning tool was detected, leaving an automated security-monitoring gap.
The repository has no security policy, leaving vulnerability reporting and response expectations unclear.
The sole workflow was fully analyzed with no high-confidence findings, no untrusted checkout, and job-level permissions, but all 8 action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rah/danpu Version ^2.7 | — | — |
smarty/smarty Version ~3.1 | — | — |
firebase/php-jwt Version ^6.11 | — | — |
guzzlehttp/guzzle Version ^7.4 | — | — |
mrgoon/aliyun-sms Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.