Clear documentation, tests, and release notes support straightforward adoption. The organization-backed project has no install-time scripts or dangerous workflow findings, though its maintenance and action-pinning practices warrant attention.
76%
Total Score
67
100
75
All 3-month commit activity came from one contributor. Organization ownership provides some handoff capacity, but no second active contributor is shown, leaving a real concentration risk.
Only 1 commit was recorded in the last 3 months, indicating limited recent development activity. The recent release and push provide some compensating evidence, so this is a maintenance caution rather than abandonment.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This is a transparency gap, not evidence of unsafe behavior.
All 3 workflows were analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 6 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^6 || ^7 || ^8 || ^9 || ^10.0.17 || ^11 || ^12.0.9 || ^13 | — | — |
php-mock/php-mock-integration Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.