An MVW PHP framework
62%
Total Score
75
100
94
83
The registry reports the latest release as July 2014 and no releases in the last 12 months, which conflicts sharply with the assessed v2.0.0 release and its published release notes. This inconsistency reduces release transparency, despite repository evidence of current work.
All four recent commits came from one contributor, creating concentrated maintenance capacity. Organization ownership provides some handoff potential, but no second recently active contributor is shown.
There are 16 open issues but no issues or pull requests were opened, closed, or merged in the last month. The lack of recent issue activity is a modest maintenance concern, not evidence of abandonment by itself.
The repository has no published security policy, leaving vulnerability-reporting expectations and response guidance unclear. The presence of security scanning partly offsets this gap but does not replace a policy.
All 16 action references are unpinned, and one release workflow has top-level write permissions; both are workflow hygiene concerns. The audit also reports high-confidence template-injection findings, but without an accompanying dangerous trigger or sink they remain hygiene rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.