MIT licensing, repository tests, and organization backing support adoption. The beta release and long two-release history add compatibility uncertainty, while six months without commits and unpinned workflow actions weaken maintenance confidence.
67%
Total Score
75
100
88
50
The package has only two releases across roughly eight years, with a median interval of about 7.6 years; the recent release shows activity but the overall history is sparse.
There were zero commits and zero active maintainers in the past three months, indicating currently quiet development despite the recent release and push history.
No security policy was found, leaving vulnerability reporting and response expectations less transparent for a configuration library.
The assessed release is v2.0.0-beta.1, so its API and behavior are explicitly not yet stable and its breaking changes require extra integration care.
Both workflows were analyzed cleanly with no injection or high-confidence audit findings, and one workflow uses read-only permissions. However, all five action references are unpinned, so their exact code is not fixed.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^5.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.