The package has a README, changelog, license, and a small dependency set. Its release workflow uses broad permissions and unpinned actions, adding maintenance hygiene concerns.
68%
Total Score
50
100
94
50
The repository recorded zero commits and zero active maintainers in the past three months. Because the release is only 185 days old, this is a meaningful sign that ongoing maintenance may have slowed.
Composer is used as the build tool, but no security scanning tools are configured. The missing scanning is a modest transparency and hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. This makes vulnerability reporting and response expectations less clear for consumers.
The only workflow was fully analyzed and has no untrusted checkout or script-injection findings, but it grants top-level write permissions, leaves both action references unpinned, and high-confidence auditing found an ad hoc package installation. These are workflow hygiene risks rather than severe standalone concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.