The repository includes tests and a changelog, and the package has a clear MIT license. Maintenance has been inactive for years, while all eight workflow action references are unpinned, so future fixes and build integrity deserve caution.
58%
Total Score
50
81
67
The package and repository are owned by the same individual account, providing consistent ownership but no organizational backing to offset the limited recent activity.
The latest release was in November 2021, with no releases in the last 12 months. This long release gap is a meaningful maintenance concern despite a previously regular release interval.
There were no commits and no active maintainers in the last three months, consistent with a project whose latest release is several years old.
There are no new or closed issues in the last month and no merged pull requests; the absence of open issues is positive, but the lack of recent activity provides little evidence of ongoing maintenance.
The repository uses Composer build tooling, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
pestphp/pest Version ^1.5 | — | — |
pestphp/pest-plugin Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.