The package includes a matching MIT license, clear documentation, repository tests, security policy, and automated dependency scanning. Its Composer setup and pinned workflow actions are reassuring, but longer-term maintenance is not yet demonstrated.
68%
Total Score
50
100
94
88
The repository is owned by the same individual namespace as the package, so ownership is consistent; individual ownership also means the visible maintainer base is limited.
Only one release exists and the package is 0 days old, so there is no historical release cadence to establish reliability or maintenance continuity.
The repository has no commits or active maintainers recorded over the last 3 months, but the package is newly released, so this primarily reflects insufficient history rather than demonstrated abandonment.
Both workflows were analyzed successfully, all five action references are pinned, and no audit findings or untrusted checkout paths were found. One workflow grants top-level write permission, which is a mild hygiene concern but has no corroborating untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-tmdb/api Version ^4.1 | — | — |
guzzlehttp/psr7 Version ^2.9|^3.0 | — | — |
guzzlehttp/guzzle Version ^7.8|^8.0 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
symfony/event-dispatcher Version ^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.