A recent tagged release, maintained repository, tests, and release notes support continued use. No commits in three months and six unpinned CI actions leave maintenance and build-integrity gaps.
70%
Total Score
75
100
88
83
The package has existed for over four years with 13 releases and a release in the last year. Only one release in the last 12 months suggests a slower cadence, though the latest release is recent.
The repository recorded no commits and no active maintainers in the last three months. For a library with a recent release, this is a meaningful sign of currently limited maintenance activity.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap, partly offset by the repository's security policy and CI workflow.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all six action references are unpinned. The missing top-level permissions block is acceptable on its own; unpinned actions remain a build-integrity hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/link Version ^1.0|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.