The package is well documented and tested, with regular releases and organization backing. Recent repository work is quiet, and both workflow action references are unpinned, leaving maintenance and build-integrity concerns.
70%
Total Score
83
100
94
63
A post-autoload-dump script runs during Composer installation, which adds install-time behavior and should be understood by consumers, but this is not severe on its own.
The repository recorded zero commits and zero active maintainers in the last three months, a meaningful sign of currently quiet development despite the recent release.
Composer build tooling is present, but no security scanning tools are reported; this is a hygiene gap rather than evidence of abandonment.
The repository has no security policy, reducing disclosure transparency for a package that manages deployment and maintenance operations.
The single workflow was fully analyzed, uses read-only permissions, and has no dangerous triggers or audit findings. However, both action references are unpinned, so their exact code is not fixed over time.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^3.3 | — | — |
team-nifty-gmbh/flux-erp Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.