A clear README, MIT licensing, regular releases, and a non-archived repository support adoption. The project lacks a security policy, has no recent commits, and uses two unpinned workflow actions; pin v1.0.6 and monitor maintenance.
61%
Total Score
50
89
50
The repository recorded zero commits and zero active maintainers in the last three months. Recent package publishing partly offsets this, but the absence of source activity is a real maintenance concern.
The repository has 6 stars, 16 forks, and 2 watchers. This is limited community evidence, though popularity is supporting evidence and does not outweigh the maintenance signals by itself.
Composer build tooling is present, but no security-scanning tool was detected. This leaves a meaningful supply-chain hygiene gap for a package with runtime dependencies.
No repository security policy was found. Without documented vulnerability reporting guidance, security transparency is weaker.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both of its two action references are unpinned, leaving them exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
tina4stack/tina4php Version ^2.0 | — | — |
bissolli/php-css-js-minifier Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.