Usable with caveats: it is a stable, licensed add-on with a recent release and a matching source repository. However, there have been no commits in the last three months, the repository has no tests or security policy, and its workflow does not declare token permissions.
68%
Total Score
63
100
94
80
Only one registry account has publishing access. The repository owner is an individual rather than an organization, so this represents a genuine bus-factor concern rather than normal organization publishing hygiene.
The artifact has a README and changelog, and the repository uses GitHub Releases, but neither the package nor repository contains tests. For a data-heavy add-on, this is a meaningful maintenance and verification gap.
The repository recorded zero commits and zero active maintainers in the last three months. The recent package release partly offsets this, but the lack of source activity still raises maintenance risk.
There are no open issues and two open pull requests, but no issues or pull requests were merged in the last month. This provides limited evidence of active project handling.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although the package's small add-on scope limits its effect on ordinary use.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-coord/php-coord Version ^5.11.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.