The repository is not archived, has tests, and documents this release with notes. Broad workflow tokens and unpinned actions add modest supply-chain hygiene concerns.
67%
Total Score
75
88
50
The package runs post-install and post-update Composer scripts. These add installation-time execution risk, although the signal does not show that the scripts are malicious or unusually broad.
The package has only 3 releases since August 2022, with a median interval of about 717 days and just 1 release in the last 12 months. The latest release is recent, but the long cadence lowers maintenance confidence.
The repository recorded 0 commits and 0 active maintainers in the last 3 months. Recent pull request activity and a recent push provide some compensation, but direct development activity still appears thin.
The repository uses Make and Composer build tooling, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it does not by itself show that the release is unsafe.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/async Version ^4.1.0 | — | — |
react/cache Version ^1.2 | — | — |
psr/simple-cache Version ^2.0 | — | — |
thecodingmachine/safe Version ^2.4.0 || ^3.0.0 | — | — |
bentools/iterable-functions Version ^2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.