Documentation and source structure are reasonably clear for a small bundle. The project has only one release, about 18 months ago, with no releases or commits in the last three months; all four workflow actions are unpinned.
55%
Total Score
0
60
50
This is the package's only release, published about 18 months ago, with no releases in the last 12 months. That leaves little evidence of ongoing maintenance for a 0.0.1 package.
There were zero commits and zero active maintainers in the last three months, which supports the broader evidence that development has stalled. The repository's later push date does not show recent commit activity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The latest version is 0.0.1 and is not a stable major release, so its API and behavior may still change substantially. The absence of prereleases does not compensate for the very early version.
Both workflows were analyzed completely and had no reported audit findings, with read-only permissions observed in one workflow. However, all four action references are unpinned, leaving workflow builds exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpinnacle/buffer Version ^1.2.0 | — | — |
workerman/crontab Version ^1.0.7 | — | — |
workerman/workerman Version ^5.1 | — | — |
fidry/cpu-core-counter Version ^1.2.0 | — | — |
symfony/framework-bundle Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.