This is a healthy, actively maintained release with a stable version, regular publishing history, a current non-archived repository, recent activity from two contributors, clear licensing, documentation, and a package layout that appears complete and directly tied to the package. The main reservations are the absence of tests and a changelog in both the artifact and repository, no repository security-scanning tooling, and workflows that do not declare top-level token permissions. These are meaningful hygiene gaps but do not outweigh the strong maintenance and project-backing evidence.
84%
Total Score
100
100
89
90
A substantial README and GitHub Releases are present, but neither the artifact nor repository contains tests or a changelog. Documentation and release evidence provide useful transparency, while the missing tests and changelog remain a maintenance-hygiene gap.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a security-hygiene limitation, though it is not evidence of abandonment by itself.
Both workflows lack top-level GitHub Actions permissions declarations. Although no workflow requests top-level write permissions, explicitly constraining permissions would provide stronger CI security hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^12 || ^13 || ^14 | — | — |
openai-php/client Version ^v0.20.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.