The package has a clear MIT license, documentation, tests in the repository, release notes, and security scanning. Maintenance is the main concern: only two releases exist and there has been no commit activity for about eight months, while the repository has very little adoption.
58%
Total Score
50
100
89
83
The package and repository are owned by the same individual account, so there is no organization backing to compensate for a small maintainer base. This is consistent with the observed limited activity but is not a severe risk alone.
There have been only two releases, both within about one day, and no further release for roughly eight months. That limited and stalled release history raises maintenance concern for a library dependency.
The repository recorded zero commits and zero active maintainers over the last three months, with the last push about eight months ago. This is the strongest evidence of stalled maintenance.
The repository has one star, three forks, and no watchers. Low popularity does not make a small package unhealthy by itself, but it provides little evidence of broad community support.
All three workflows were analyzed without trigger or untrusted-checkout findings, but every one of seven action references is unpinned and the audit found a high-confidence unpinned container image. This is a workflow hygiene concern, not a severe dependency risk on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
codeigniter4/framework Version ^4.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.