The package has a stable release line, regular registry releases, and no install-time scripts. Its single-maintainer setup and missing security policy leave less operational depth.
72%
Total Score
50
100
94
67
Only one account has registry publish access. Because the repository is also owned by that same individual and releases continue, this is a limited bus factor rather than evidence of abandonment.
The repository had zero commits and zero active maintainers in the last 3 months, despite four registry releases in the last year. The release cadence partly offsets this, but recent source activity is still quiet.
Composer is used for builds, but no security scanning tools were detected. The missing scanning coverage is a modest transparency and maintenance concern, not a severe risk by itself.
No repository security policy was found. This reduces clarity about vulnerability reporting and response, although it does not by itself indicate unsafe code.
The single workflow was fully analyzed with no trigger or injection findings, but all 6 action references are unpinned. The workflow also lacks a top-level permissions block; this is acceptable on its own, while unpinned actions remain a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nette/neon Version ^3.4 | — | — |
fakerphp/faker Version ^1.24 | — | — |
macocci7/php-plotter2d Version ^1.0 | — | — |
macocci7/php-frequency-table Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.