The package includes tests and a focused seven-file tree, with only two runtime dependencies. Organization backing and a stable major release provide useful continuity, while unpinned workflow actions leave build provenance weaker.
64%
Total Score
75
100
88
67
No license declaration, license file, or repository license file was detected, leaving legal reuse terms unclear for adopters.
The repository recorded zero commits and zero active maintainers during the last 3 months, indicating a recent pause in development despite the recent registry release.
Composer is used for builds, but no security-scanning tooling was detected. For this small package, that weakens assurance without making it unfit to adopt.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all 3 action references are unpinned, weakening build reproducibility and provenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scriptfusion/static-class Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.