The project has substantial recent commit activity, tests, documentation, and an organization-owned repository. Maintenance is concentrated in one contributor, while the workflow uses two unpinned actions and the repository has no security policy or scanning.
68%
Total Score
83
79
50
The package is extremely new, with two releases over roughly one day, so long-term maintenance and release stability cannot yet be established.
All 113 recent commits came from one contributor, creating a meaningful continuity risk; organization ownership provides some capacity for handoff but does not remove the concentration.
Composer build tooling is present, but no security-scanning tooling was detected, leaving an avoidable maintenance and supply-chain hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
Version 0.1.1 is not a stable major release, which indicates an API that may still change substantially despite having no prerelease marker.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sigmaphp/sigmaphp-filesystem Version ^0.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.