Version 9.0.3 appears healthy to depend on: the package has a long release history dating from 2016, 213 releases, 12 releases in the last 12 months, and a recent stable release. Its repository is active and not archived, with 80 commits from four maintainers in the last three months, substantial pull-request merging, tests, a changelog, build tooling, Dependabot scanning, and no observed dangerous workflow patterns. Licensing and package structure are clear, and the repository README references the package despite the repository name differing from the package name. The main reservations are the absence of a security policy and explicit top-level workflow permissions, which are repository hygiene gaps rather than evidence of abandonment; the package's low popularity is also only a modest concern.
91%
Total Score
100
100
94
80
The repository has 27 stars, 29 forks, and 8 watchers, which is modest popularity. This is only a minor caution because popularity is supporting evidence and the activity signals are strong.
No SECURITY.md or equivalent security policy was found, reducing vulnerability-reporting transparency. This is a genuine hygiene gap but not evidence that the package is unmaintained.
All 4 workflows lack top-level permissions declarations. Although none declares top-level write access, explicit least-privilege permissions would provide stronger CI security assurance.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nosto/php-sdk Version 8.0.0 | — | — |
magento/framework Version >=101.0.6|~104.0 | — | — |
laminas/laminas-uri Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.