The package has a clear MIT declaration, a usable README, tests, and release notes for this version. Its small maintainer base and unpinned workflow actions merit monitoring, but organization backing and read-only workflow permissions reduce the concern.
78%
Total Score
67
100
94
67
One contributor made all three commits in the last three months, creating a concentrated maintenance dependency. Organization ownership provides some handoff capacity but no second active contributor is shown.
The repository recorded three commits in the last three months, all from one active maintainer. Recent activity exists, but the pace is modest relative to the package's release cadence.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene gap.
No security policy was detected in the linked repository, reducing transparency about how vulnerabilities should be reported.
The single workflow uses read-only permissions and has no detected injection or high-severity findings, but all three action references are unpinned, which weakens build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
jobcloud/php-kafka-lib Version ~2.0.0 | — | — |
laravel/lumen-framework Version ^11.2.0 | — | — |
flix-tech/avro-serde-php Version ~2.1.0 | — | — |
coraxster/flysystem-aws-s3-v3-minio Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.