Tests, MIT licensing, and organizational ownership provide solid foundations. Releases have been infrequent, recent commit activity is absent, workflow dependencies are unpinned, and no security policy is published.
64%
Total Score
75
100
92
67
The package has only 5 releases since August 2020, with no releases in the last 12 months and a median interval of about 409 days. This indicates slow maintenance, although the repository remains active enough to avoid an abandonment verdict.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, which is a meaningful maintenance concern. The repository was pushed recently overall, so this supports caution rather than severe abandonment risk.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities. This is a moderate gap, partly offset by the repository's tests and complete workflow audit.
The single analyzed workflow was audited completely and has no reported dangerous findings or write permissions, but all 3 action references are unpinned. That is a supply-chain hygiene gap, not a severe risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-etl/bucket-contracts Version 0.3.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.