The package includes tests, release notes for this version, and automated dependency and static-analysis tooling. Maintenance has since slowed, with no commits or issue activity in the measured recent period, and all workflow actions are unpinned.
62%
Total Score
67
100
94
75
The package has 22 releases over more than seven years, but no releases in the last 12 months and its latest registry release was in December 2022, indicating substantial release inactivity.
The repository recorded zero commits and zero active maintainers in the measured three-month period, which is a concrete sign of slowed maintenance.
There were no new or closed issues or pull requests in the measured month, while several issues and pull requests remain open; this suggests limited recent maintenance attention.
No repository security policy was found. This is a minor transparency gap for a small testing module, not evidence that the package is unsafe to use.
The single workflow was fully analyzed with no trigger, injection, or high-severity findings, but all 10 action references are unpinned, leaving avoidable update and supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/semver Version ^1.4 || ^2.0 || ^3.0 | — | — |
codeception/module-cli Version ^1.0.0 || ^2.0.0 | — | — |
codeception/codeception Version ^4.1.31 || ^5.0 | — | — |
codeception/module-filesystem Version ^1.0.2 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.