The package is well documented, licensed, and backed by a matching organization repository with tests and release notes. Its source repository is archived, registry listing is marked abandoned, and there have been no commits or releases for roughly two years; workflow credential and pinning hygiene also needs attention.
12%
Total Score
75
64
75
Packagist marks the entire package as abandoned, with no replacement supplied. This is a direct warning against taking a new dependency on the package.
The linked source repository is archived, which strongly indicates that normal maintenance and issue response have ended. This is severe abandonment risk despite the recorded push timestamp.
The package has 18 releases over about nine years, but none in the last 12 months; the latest release was roughly two years ago. The earlier cadence provides maturity but does not offset the current inactivity.
There were zero commits and zero active maintainers in the last three months. Combined with the archived repository and abandoned registry status, this supports a conclusion of inactive maintenance.
All seven analyzed action references are unpinned, and high-confidence secrets-inherit findings appear across the workflows. No untrusted checkout or script-injection paths were found, so this is a workflow hygiene concern rather than the primary health risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2 | — | — |
phpcompatibility/php-compatibility Version ^9.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.