Usable with caveats: the package is licensed, correctly backed by its repository, and has release documentation and security tooling. However, it has had no registry release in nearly three years and no commits or active maintainers in the last three months, so ongoing maintenance is uncertain.
62%
Total Score
63
100
94
80
The repository recorded zero commits and zero active maintainers during the last three months, a concrete sign that maintenance may have stalled despite the repository not being archived.
One workflow uses pull_request_target for Dependabot auto-merge, which warrants review because that trigger can run with elevated repository context; no untrusted checkout or script-injection findings were detected.
Although the package released regularly at first, its latest registry release was nearly three years ago and it has had no releases in the last 12 months, which raises maintenance and compatibility concerns.
There are no open issues and four open pull requests, but none were merged or newly created in the last month, suggesting limited recent project activity.
Four of five workflows omit top-level permissions and the Dependabot auto-merge workflow grants write access, leaving workflow token scope less explicit than ideal.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
nunomaduro/phpinsights Version ^2.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.