The package has a long release history, a stable version, repository tests, and a clear MIT license. No commits were recorded in the last three months, while workflow images are unpinned and no security policy is present.
68%
Total Score
75
93
75
The repository recorded zero commits and zero active maintainers in the last three months, which is a meaningful sign of slowed maintenance; the recent push provides only limited compensation.
Composer build tooling is present, but no security scanning tools were detected, leaving repository-level security hygiene weaker than it could be.
The repository has no security policy, reducing transparency about how maintainers handle vulnerability reports.
Both workflows were analyzed successfully, but all 3 action references are unpinned and a high-confidence finding reports an unpinned container image. The pull_request_target trigger has no untrusted checkout or script-injection sink, so it is not independently dangerous.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
konekt/enum Version ^4.2 | — | — |
konekt/user Version ^3.0 | — | — |
konekt/address Version ^3.4.1 | — | — |
konekt/concord Version ^1.15 | — | — |
vanilo/support Version ^5.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.