Faker extension to include es_ES locale
68%
Total Score
caution
Usable with caveats: six months without commits and all five workflow actions are unpinned.
Only two releases have appeared across 461 days, with one release in the last 12 months and a median interval of about 209 days. That is a slow cadence, though reasonable for a small locale extension.
There were zero commits and zero active maintainers in the last three months, while the repository was last pushed about six months ago. This is meaningful evidence of currently slow maintenance.
Composer build tooling is present, but no security-scanning tool was detected. For a small PHP extension this is a modest transparency gap rather than a severe risk.
The repository has no security policy. This weakens vulnerability-reporting transparency, although it does not by itself indicate abandonment.
All five analyzed action references are unpinned, so workflow dependencies can change without a repository change; the two workflows were fully analyzed and had no reported findings or untrusted triggers. The absence of top-level permissions is not a concern here, with one workflow using job-level permissions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
xefi/faker-php Version ^1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.