A security policy is absent, and both workflow actions are unpinned. The package includes tests, a clear README, a matching MIT license, and release notes, which provide useful maintenance and usage evidence.
58%
Total Score
50
90
50
The latest release was over three years ago, with no releases in the last 12 months. This is meaningful staleness for a dependency, although the package has a long history and six releases overall.
The repository recorded no commits and no active maintainers in the last three months, corroborating the lack of recent releases and raising abandonment risk.
There were no new or closed issues or pull requests in the last month, while six issues remain open. This suggests limited current project activity.
The repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The absence of security scanning tools provides no compensating evidence.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both of its action references are unpinned, leaving avoidable build-reproducibility and update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
yiisoft/yii2 Version ^2.0.35 | — | — |
php2wsdl/php2wsdl Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.