Tests, a readable package guide, and a matching Apache-2.0 license provide useful adoption basics. The lack of recent development and fully unpinned workflow actions make long-term maintenance and build integrity uncertain.
45%
Total Score
0
70
50
The package has only one release, published about 1 year and 9 months ago, with no releases in the last 12 months. This provides little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, reinforcing the risk that this fork is no longer being maintained.
The linked repository has zero stars, forks, and watchers. Popularity is not required for a healthy package, but these values provide no supporting evidence of an active user or maintainer community.
The repository has no security policy, which reduces transparency about reporting and handling vulnerabilities. The package's license and test coverage provide some project structure but do not replace this process documentation.
Both workflows were analyzed successfully and contain no dangerous triggers, untrusted checkouts, or script-injection findings. However, all 5 action references are unpinned, leaving workflow dependencies less reproducible and increasing update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
swoft-fork/stdlib Version ~2.1.0 | — | — |
doctrine/annotations Version ^1.4 | — | — |
php-di/phpdoc-reader Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.