Clear licensing and repository tests add useful transparency. The workflow files leave all 16 actions unpinned, creating a modest reproducibility concern.
78%
Total Score
83
88
67
The package and repository are owned by the same individual account, so there is no organization-backed handoff signal. Other evidence of four active contributors partly offsets that limitation.
There have been no registry releases in the last 12 months, which is a maintenance concern. However, the repository shows recent commit activity, partly compensating for the stale registry cadence.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a minor governance gap for a maintained package.
Both workflows were fully analyzed with no injection or high-severity findings, but all 16 action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene without making the release unfit on their own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
fossar/htmlawed Version ^1.3.3 | — | — |
guzzlehttp/psr7 Version ^2.0 | — | — |
monolog/monolog Version ^3.0 | — | — |
php-http/httplug Version ^2.4 | — | — |
php-http/message Version ^1.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.