The repository remains unarchived and has tests plus release notes. Maintenance is concentrated in one contributor, and all four workflow actions are unpinned.
20%
Total Score
50
71
Packagist marks the package abandoned and points users to firstred/postnl-api-php. Package-level abandonment is a severe adoption risk even though the linked repository remains available.
The latest registry release was in January 2022, with no releases in the last 12 months. That is more than four years without a package release and raises compatibility and abandonment concerns.
All two recent commits came from one contributor, leaving maintenance highly concentrated and increasing continuity risk.
The repository recorded only two commits in the last three months, indicating limited current maintenance activity despite the repository not being archived.
The single analyzed workflow has no unsafe trigger or audit finding, but all four referenced actions are unpinned. This is a supply-chain hygiene gap in the build process.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
psr/cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
setasign/fpdf Version ^1.8 | — | — |
setasign/fpdi Version ^2.0 | — | — |
guzzlehttp/psr7 Version ^1.7 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.