The package includes consumer documentation, repository tests, and release notes, with organization backing and no deprecation or install-time scripts. Recent commit activity is absent, while the license mismatch and unpinned workflow dependency reduce transparency and maintenance confidence.
67%
Total Score
83
100
88
75
The artifact and repository contain license files, but the manifest declares BSD-3-Clause while the detected license is BSD-2-Clause. That mismatch creates a genuine transparency concern despite the presence of licensing.
The repository recorded zero commits and zero active maintainers in the last three months. Although a release and push occurred recently, the absence of ordinary recent development activity is a maintenance concern.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest hygiene gap, not evidence of abandonment by itself.
The repository has no security policy. For a small package this is a transparency gap, though it is less consequential than evidence of active maintenance or a deprecation notice.
The sole workflow was fully analyzed with no dangerous audit findings or untrusted triggers, but its one action use is unpinned. The absent top-level permissions block is acceptable on its own, while the unpinned reference is a minor supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
silvershop/core Version ^4 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
willdurand/geocoder Version ^4.0 | — | — |
php-http/guzzle7-adapter Version ^1.0 || ^2 | — | — |
geocoder-php/chain-provider Version ^4.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.