Its 60 runtime dependencies increase upgrade and compatibility work, while all six workflow actions are unpinned. The project still includes tests, release notes, a security policy, and an active, non-archived repository.
62%
Total Score
50
50
100
75
The release declares 60 runtime dependencies, creating substantial compatibility and upgrade coordination risk for consumers. This is a real complexity cost, though the profile is explicit rather than missing.
The package runs post-install and post-update Composer scripts, increasing installation-time behavior and review surface. No other provided signal shows these scripts are unsafe, so this is a modest hygiene concern rather than a severe risk.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Recent registry releases provide some compensating evidence, but the lack of observed source activity remains a maintenance concern.
All 6 analyzed action references are unpinned, which leaves workflow dependencies exposed to moving revisions. Read-only permissions, no untrusted checkouts, no injection findings, and a complete audit reduce the severity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
se7enxweb/ezie Version ~6.0.0 | — | — |
se7enxweb/ezwt Version ~6.0.0 | — | — |
se7enxweb/bccie Version ~1.1.3 | — | — |
se7enxweb/ezodf Version ~6.0.0 | — | — |
se7enxweb/swark Version ~1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.