The stable release history and organization-owned repository provide useful continuity. Workflow pinning and security documentation are weaker than ideal.
68%
Total Score
75
100
94
67
All recent repository activity consists of one commit from one contributor, giving the project a fully concentrated recent bus factor. Organization backing provides some handoff capacity, but no second active contributor is evidenced.
Composer build tooling is present, but no security scanning tools were detected. That weakens automated oversight without indicating abandonment by itself.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The only workflow was fully analyzed with no audit findings or untrusted-code sinks, but all 3 action references are unpinned. The absence of a top-level permissions block is not concerning on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phant/error Version 1.* | — | — |
aws/aws-sdk-php Version 3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.