A single contributor has made all 16 recent commits, and every action reference is unpinned. The long release history, current release notes, tests, license, and security policy provide useful counterweight.
68%
Total Score
67
100
86
100
The repository is owned by an individual account rather than an organization, so the concentrated recent commit activity is not offset by visible organizational handoff capacity.
One contributor made 100% of the 16 recent commits. This concentrates maintenance knowledge and raises continuity risk for a user-owned project.
The repository name does not match the package name and its README does not mention the package. That mismatch makes package-to-source linkage less transparent, although the repository contents are clearly module-oriented.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and review gap, not evidence of an unsafe release by itself.
All four workflows were analyzed without findings or untrusted-code sinks, but all five action references are unpinned. Unpinned actions can change unexpectedly and weaken build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.17 | — | — |
psr/log Version ^3.0.2 | — | — |
ray/aop Version ^2.17 | — | — |
twig/twig Version ^v3.15 | — | — |
bear/sunday Version ^1.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.