Regular releases, tests, release notes, and organizational ownership support continued maintenance. Its workflow setup still needs attention before trusting automated publishing.
65%
Total Score
67
100
100
75
One contributor made all 2 commits in the last 3 months. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Only 2 commits were recorded in the last 3 months, showing limited recent source activity despite the recent release cadence.
No repository security policy was found, leaving vulnerability-reporting guidance unclear.
All 43 analyzed action references are unpinned, and high-confidence artipacked and template-injection findings affect release workflows. The low-confidence cache finding is not material on its own; no untrusted checkout or dangerous trigger was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sentry/sentry Version ^1.11.0 | — | — |
vlucas/phpdotenv Version ^3.4 | — | — |
segmentio/analytics-php Version ^1.5 | — | — |
facebook/php-business-sdk Version dev-remove-guzzle | — | — |
prestashopcorp/module-lib-billing Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.