Clear documentation, release notes, and a clean workflow audit improve adoption confidence. Organization backing helps offset one-person commit concentration, but all four actions are unpinned and no security scanning is reported.
78%
Total Score
67
100
94
83
One contributor made 100% of the 10 recent commits. The organization-owned repository provides some handoff capacity, but the observed maintenance activity remains highly concentrated.
The repository recorded 10 commits in the last three months, showing current maintenance. However, all of those commits came from one active maintainer, which limits visible redundancy.
Composer is used for builds, which supports reproducible package management, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap rather than evidence of an unsafe release.
Both workflows were analyzed without failed files, injection sinks, dangerous triggers, or audit findings. All four action references are unpinned, which leaves dependency versions floating and is a minor supply-chain hygiene concern.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10546 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. phpmussel/frontend is vulnerable to Path Traversal in versions 3.0.0 - 3.6.2. | 3.0.0 - 3.6.2 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpmussel/core Version ^3.7 | — | — |
maikuolan/common Version ^2.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.