The source remains active, documented, tested, and backed by an organization. Adopt matomo/matomo-php-tracker instead, because this package has been withdrawn under its old name; workflow pinning also needs attention.
22%
Total Score
100
75
50
Packagist marks the entire package as abandoned and names matomo/matomo-php-tracker as its replacement. This is a direct adoption risk despite the recent release and active repository.
The repository name does not match piwik/piwik-php-tracker and its README does not mention that package. This creates uncertainty about whether the old registry package is the intended published project.
The repository has no security policy file. This reduces vulnerability-reporting transparency, though the active organization backing and security scanning provide partial compensation.
Both workflows were analyzed with read-only permissions and no dangerous triggers or audit findings, but three of six action references are unpinned. This is a limited supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.