PHP stubs for Moodle LMS — classes, functions, constants, and global variables for IDE and static analysis support
68%
Total Score
caution
Usable with caveats: all workflow actions are unpinned and the repository lacks security tooling.
Only one registry maintainer is listed, and the repository is owned by the same individual. That is adequate for a small project but leaves little visible publishing redundancy if the maintainer becomes unavailable.
The repository recorded zero commits and zero active maintainers in the last three months, despite the registry showing frequent releases. This weakens evidence of active source development and makes the release process look largely automated.
Composer is used as the build tool, but no security-scanning tool is configured. The missing scanner is a hygiene gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md or other security policy. For a package providing a large set of code stubs, this reduces transparency about how defects or security-sensitive issues should be reported.
All 9 analyzed action references are unpinned, so workflow dependencies can change without a source update. The high-confidence template-injection finding is a workflow hygiene concern, but there were no untrusted checkouts, script injections, dangerous triggers, or top-level write permissions, which limits its impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.