The repository includes tests, release notes, and a matching package source, while the organization has kept it active through the current release. No security policy, security scanning, and pinned workflow actions leave modest maintenance and build-transparency gaps.
78%
Total Score
88
100
94
83
There were no commits and no active maintainers in the three months measured. This is a caution for current maintenance capacity, although the recent v2.5.0 release and repository push provide compensating evidence.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP test integration package this is a modest transparency gap, not evidence that the release is unsafe.
The repository has no security policy. This weakens the documented process for reporting vulnerabilities, though it does not indicate abandonment on its own.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all 6 action references are unpinned, so their contents can change without a version pin.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.1 || ^10.1 || ^11.0 || ^12.0 || ^13.0 | — | — |
phpspec/prophecy Version ^1.18 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.