The MIT license, tests, and matching repository make the project easy to inspect. Security coverage is absent and workflow dependencies are unpinned, leaving little evidence of ongoing upkeep.
40%
Total Score
50
88
50
The latest release was over five years ago, with no releases in the last 12 months. The package is not deprecated, but this release history indicates substantial abandonment risk.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap and weakening confidence in future maintenance.
The repository has no security policy and no security-scanning tools, reducing transparency and leaving no documented process for handling vulnerabilities.
The workflow audit completed cleanly with no dangerous triggers or audit findings, but both action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
nigatedev/diyan Version ^1.0 | — | — |
vlucas/phpdotenv Version ^5.3 | — | — |
nigatedev/console Version ^1.0 | — | — |
nigatedev/support Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.