The repository has tests, release notes, a matching README, and an MIT license. Unpinned workflow actions and no security policy add hygiene risk, while maintenance activity appears limited.
58%
Total Score
83
100
88
83
The package has had no release since March 2022, despite 14 releases since 2016; this is a meaningful maintenance and abandonment concern, though the repository was pushed in November 2024.
There were no commits and no active maintainers in the last three months. Combined with no releases since March 2022, this points to limited current maintenance, although the repository was pushed in November 2024.
The repository uses Composer and Make for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package that instruments application execution.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, which leaves the build exposed to changes in referenced actions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
recoil/api Version ^1 | — | — |
nikic/php-parser Version ^4 | — | — |
eloquent/enumeration Version ^5 | — | — |
hamcrest/hamcrest-php Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.