The repository has tests, a matching source tree, organizational backing, and a clearly documented MIT license. Unpinned workflow actions, no security policy, install-time scripts, and a very small release history add maintenance and supply-chain hygiene concerns.
62%
Total Score
75
79
50
The package defines post-install and post-update Composer scripts. These increase installation complexity and the code executed during dependency operations, so they are a modest hygiene concern.
The package has only 5 releases and none in the last 12 months; its latest registry release was over two years ago. This is a meaningful maintenance concern, although the linked repository was pushed more recently.
There were no commits and no active maintainers in the three months before collection. Although the repository has a recent push, the observed short-term development activity is weak.
Composer build tooling is present, but no security-scanning tools were detected. This limits automated coverage of dependency and code risks.
The repository has no security policy. That reduces transparency about how vulnerabilities should be reported and handled, though it does not by itself show unsafe code.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.