Regular releases and a current repository indicate ongoing maintenance. The package also has useful documentation, tests, a changelog, a license, and a security policy.
72%
Total Score
67
94
100
One contributor made all recent commits, creating a concentrated maintenance dependency. Organization backing provides some continuity, but no second active contributor is shown.
Only 4 commits were made in the last 3 months, by one active maintainer; this shows activity but leaves limited maintenance capacity.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The single workflow was fully analyzed with no untrusted checkout or script-injection path, but it has a high-confidence finding because its container image uses the floating latest tag.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
edamov/pushok Version ^0.19 | — | — |
symfony/cache Version ^6.4|^7.0 | — | — |
google/apiclient Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.