It includes tests, a matching MIT license, and a GitHub release for this version. The workflows have no audit findings, but all three actions are unpinned and the repository has no security-scanning tools.
63%
Total Score
0
50
86
The repository recorded zero commits and zero active maintainers in the last three months. With only two releases, this is a notable maintenance-risk signal rather than evidence of mature stability.
The package declares nine runtime dependencies, including framework and ORM components, creating meaningful transitive maintenance exposure for a small testing utility.
There have been two releases over roughly 11 months, with the latest published about nine months ago. This shows some release activity but provides limited evidence of an established cadence.
Composer build tooling is present, but no security-scanning tools were detected. This is a hygiene gap that lowers transparency without showing abandonment by itself.
Both workflows were analyzed successfully with no findings, no untrusted checkouts, and no script injection. However, all three action references are unpinned, leaving avoidable build-reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3|^2|^1 | — | — |
doctrine/orm Version ^3.0 | — | — |
monolog/monolog Version ^3.1 | — | — |
symfony/http-kernel Version ^7.3 | — | — |
league/construct-finder Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.