Composer tooling and Psalm scanning provide useful build and code-quality support, and the package has a clear license. A single maintainer and small user base leave limited redundancy when maintenance is needed.
54%
Total Score
50
92
75
One registry maintainer is consistent with a user-owned project, but it provides little contributor redundancy if the maintainer becomes unavailable.
This is the only release, published about two years ago, with no releases in the last 12 months. The linked repository is still active rather than archived, but release evidence is thin.
The repository had zero commits and zero active maintainers in the last three months. That indicates limited recent maintenance, although it is not proof of abandonment by itself.
The repository has no published security policy. For a small library this is a transparency gap, even though the absence does not indicate a security defect.
All 9 analyzed action references are unpinned, reducing build reproducibility and leaving dependency versions exposed to upstream changes. The audit found no untrusted checkouts, script injection, or broad top-level write permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
marcosh/lamphpda Version ^3.1.1 | — | — |
giorgiosironi/eris Version ^1.0.0-rc2 | — | — |
marcosh/lamphpda-optics Version ^0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.