Clear documentation, tests, and release notes reduce adoption friction. Organization backing and security scanning help, while unpinned workflow references and the missing security policy weaken operational transparency.
61%
Total Score
75
94
50
A post-install command runs during installation. This is a modest supply-chain and reproducibility consideration, though the signal alone does not show harmful behavior.
The package has had no releases in the last 12 months, and its latest release was 1 year 9 months ago. This weakens confidence in ongoing maintenance despite nine releases overall.
There were no commits and no active maintainers in the last 3 months. Although the repository was pushed recently, the measured commit silence is a meaningful maintenance concern.
The repository has no published security policy. This reduces transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or high-severity issues. However, all 3 of 3 action references are unpinned, leaving builds exposed to moving action revisions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
intouch/newrelic Version ^2.0 | — | — |
not-empty/ulid-php-lib Version ^7.0 | — | — |
laravel/lumen-framework Version ^10.0 | — | — |
not-empty/jwt-manager-php-lib Version ^7.0 | — | — |
not-empty/response-json-php-lib Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.