The package is licensed, includes repository tests and a changelog, and has a security policy. Its organization-backed project has no recent issue activity, leaving ongoing support uncertain.
60%
Total Score
75
100
94
75
The package runs post-install and post-update Composer scripts, increasing installation complexity and execution surface, although this is common in the ecosystem and no related workflow finding was reported.
The latest release was about 21 months ago, with no releases in the last 12 months. Six releases over roughly four years show an established but currently inactive cadence.
The repository recorded no commits and had no active maintainers in the last three months, which raises maintenance and abandonment concerns despite the non-archived status.
All 25 analyzed action references are unpinned, creating avoidable workflow supply-chain drift; two workflows also grant top-level write permissions. No untrusted checkout, script injection, or auditor findings were reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0.0 | — | — |
orisai/exceptions Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.