The package is licensed, documented, tested in the repository, and not deprecated. A single maintainer, no commits in the last three months, no security policy, and unpinned workflow actions warrant caution.
67%
Total Score
50
100
50
One registry account has publish access. This is a thin publishing base for a user-owned project and modestly increases continuity risk, though recent release activity provides some compensation.
The repository had no commits and no active maintainers during the last three months. The recent release and push show some continued activity, but the current maintenance pace is quiet.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although the repository does include Psalm security scanning.
Both workflows were analyzed completely with no untrusted checkouts or script-injection findings, but all 5 action references are unpinned. The informational unsound-contains findings are hygiene issues rather than severe workflow risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phplucidframe/console-table Version ^1.2 | — | — |
phrozenbyte/phpunit-throwable-asserts Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.