The repository is not archived and includes tests, a substantial README, and release notes for this version. Maintenance has slowed, with no commits in the last three months, while all three workflow actions are unpinned and no security policy is present.
65%
Total Score
75
88
67
The package has 32 releases over more than three years and one release in the last 12 months; the latest release was published about seven months before collection. This shows ongoing availability but a slower recent cadence.
The repository recorded zero commits and zero active maintainers in the last three months. Even with a push about five months earlier, this indicates limited current maintenance activity.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a modest repository-hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. This reduces transparency about vulnerability reporting and handling, though the package's tests, license, and active repository status provide some compensating evidence.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or high-severity findings. However, all three action references are unpinned, leaving build inputs less reproducible and increasing dependency-hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
aws/aws-sdk-php Version ^3.2 | — | — |
monolog/monolog Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.