The project has tests, release notes, regular releases, and organizational backing. Its small active contributor base, absent security policy, and unpinned workflow actions leave maintenance continuity and build integrity less certain.
68%
Total Score
75
94
67
Only one contributor made recent commits, with that contributor responsible for 100% of the last three months' commits; organizational backing partly offsets this concentration but does not remove the continuity risk.
The repository recorded 8 commits in the last 3 months, showing ongoing work, though all recent commits came from one active maintainer.
Composer is used for the build, but no repository security scanning tools were detected, leaving dependency and code issues with less automated coverage.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
Both workflows were analyzed successfully with no dangerous triggers, injection findings, or high-severity audit results, and one workflow has read-only permissions. However, all 5 action references are unpinned, which weakens build reproducibility and supply-chain integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^v2.2.2 | — | — |
symfony/cache Version ^v5.4.42 | — | — |
bjeavons/zxcvbn-php Version ^1.0 | — | — |
phpmailer/phpmailer Version ^6.5.0 | — | — |
mxrxdxn/pwned-passwords Version ^v2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.