Access Azure Keyvault from PHP
58%
Total Score
caution
Usable with caveats: no releases in about four years and no recent commit activity.
The package has had no registry release in about four years, with only three releases overall; this is a meaningful maintenance and abandonment concern.
There were no commits and no active maintainers in the last three months, reinforcing the concern raised by the long gap since the latest registry release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version 0.2.0 is not a stable major release, so the API may still change; the presence of release notes provides some evidence of deliberate versioning but does not remove that risk.
All 10 analyzed action references are unpinned, which weakens build reproducibility. The audit also failed for one file, although it found no untrusted checkout, script injection, or high-severity findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.4 | — | — |
psr/http-client Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.