The package has tests, a matching organization-owned repository, and a clear BSD-2-Clause license. Unpinned workflow actions and the absence of a security policy reduce transparency and build confidence.
58%
Total Score
75
86
83
The package has 49 releases and a historically regular median interval of about 12 days, but it has had no releases in over three years. That long release gap is a meaningful maintenance concern.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing no release in over three years. This points to currently inactive maintenance.
The repository uses Composer build tooling, but no security scanning tool was detected. For a maintained library, that is a modest transparency and assurance gap.
No security policy was found in the repository. This weakens the project's documented process for handling vulnerabilities, though it is not by itself evidence of unsafe code.
The single workflow was fully analyzed with no reported audit findings or untrusted checkouts, but all four action references are unpinned. Unpinned actions weaken build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.