Clear documentation, licensing, release notes, and a clean workflow audit support adoption. Maintenance depends on one recent contributor, while 524 issues remain open and workflow references are unpinned.
70%
Total Score
63
100
94
75
The repository is owned by a user account rather than an organization, so the single-contributor concentration is not visibly compensated by organizational backing.
All 16 commits in the last three months came from one contributor, leaving maintenance highly concentrated and increasing continuity risk for a user-owned project.
The repository has 524 open issues, with no issues closed in the last month and no pull requests merged in that period. This indicates a meaningful maintenance backlog despite two new pull requests.
Composer build tooling is present, but no security-scanning tools were detected. That is a modest transparency and maintenance gap, not evidence of a specific vulnerability.
The repository has no security policy, so the process for reporting and handling security issues is not documented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mike42/gfx-php Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.