Clear documentation, licensing, tests, and repository alignment reduce adoption friction. However, the last release was over five years ago and repository activity stopped over four years ago, while one workflow uses an archived action.
57%
Total Score
63
100
89
88
Only six releases were published, with no release in the last five years; this materially raises abandonment and compatibility risk for a maintained integration library.
There were zero commits and zero active maintainers in the last three months, reinforcing that development has effectively stopped for a package last released over five years ago.
There is only one open issue and no recent issue or pull-request activity. This is consistent with a quiet project but provides no evidence of active support.
Both workflows were analyzed completely with no untrusted checkouts or script injection, and no broad top-level write permissions. All five action references are unpinned and one high-confidence medium-severity finding uses an archived action, creating a maintenance and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.163 | — | — |
aws/aws-php-sns-message-validator Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.