The license texts disagree, and all three workflow actions are unpinned. Tests, a readable guide, an active repository, and no deprecation offset some of that risk.
62%
Total Score
75
83
67
The manifest declares BSD-3-Clause, while the artifact license file was detected as BSD-2-Clause. A license is present, but the mismatch creates avoidable uncertainty about the intended terms.
The latest release was published in March 2022, with no releases in the past 12 months. The repository was pushed in October 2025, which suggests some project activity but does not show current release maintenance.
There were no commits and no active maintainers in the past 3 months. This reinforces the concern about the absence of recent registry releases, although the repository had a later push in October 2025.
The repository has no SECURITY.md or other declared security policy. This is a transparency and response-process gap, though it is not evidence of a vulnerability.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 3 action references are unpinned. The missing top-level permissions block is acceptable on its own and no write-wide token was observed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
netherphp/ki Version >=1.0 | — | — |
netherphp/stash Version >=2.0 | — | — |
phpunit/phpunit Version ^9.5 | — | — |
netherphp/object Version >=3.0 | — | — |
netherphp/option Version >=1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.