It includes tests, a matching repository, and no install scripts. The missing license and unpinned workflow actions reduce transparency and build reproducibility.
55%
Total Score
75
75
100
Neither the package nor its repository declares or includes a detected license. That creates a material legal and adoption risk for dependents.
The latest release was in October 2022, with no releases in the last 12 months and a release history of only nine versions over nearly ten years. This indicates prolonged maintenance inactivity.
There were no commits and no active maintainers in the last three months, consistent with nearly four years without a new release. This is a significant abandonment concern.
The repository uses Composer but has no security scanning tools. For a small PHP library this is a hygiene gap, though the package's tests provide some compensating quality evidence.
The single workflow was fully analyzed with no dangerous triggers, sinks, or audit findings, but all three action references are unpinned. The unpinned actions weaken build reproducibility without indicating an immediate severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
scriptfusion/retry Version ^1|^2|^3|^4|^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.