The MIT license, tests, README, and release notes provide useful transparency. However, the registry marks the package abandoned and its source repository is archived, making future fixes and support unreliable.
15%
Total Score
50
64
100
Packagist marks the entire package as abandoned with no replacement, which is a severe dependency and support risk for this release.
The repository recorded zero commits and zero active maintainers in the last three months, reinforcing the abandonment concern rather than compensating for it.
The linked repository is archived, despite a push about eight months before collection; archived projects are not dependable for ongoing fixes or maintenance.
The package has existed since 2019 with 14 releases and two releases in the last 12 months, showing prior maintenance, but this does not offset the current abandonment and archive status.
Both workflows were analyzed with no audit findings, no untrusted checkouts, and no script injection; however, both action references are unpinned, a minor reproducibility and update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
predis/predis Version ^2.0 | — | — |
tastyigniter/core Version ^v4.0 | — | — |
symfony/postmark-mailer Version ^7.3 | — | — |
league/flysystem-aws-s3-v3 Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.