The package is clearly identified, licensed, documented, and has repository tests. Its small ownership base and lack of security scanning leave less operational depth than a strongly maintained dependency.
68%
Total Score
63
100
94
75
Only one registry account has publish access. That is a modest continuity risk for a user-owned project, although the repository shows an established release history.
The repository is owned by an individual rather than an organization, so there is no organizational backing to compensate for the single registry maintainer.
The repository recorded zero commits and zero active maintainers in the last three months. The recent release and same-day push partially offset this, but ongoing maintenance activity is currently thin.
The repository uses Make, Composer, and Box for builds, showing structured packaging, but no security-scanning tools were detected.
The repository has no published security policy, which reduces transparency for reporting and handling security problems.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.