A Pest runner
68%
Total Score
caution
Usable with caveats: maintenance has paused recently and workflow dependencies are not pinned.
The package declares 11 runtime dependencies, including framework, testing, and Composer components. This is a meaningful dependency surface but is consistent with a Craft CMS testing integration.
The package and repository are owned by the same individual account. This is coherent ownership, but it provides less organizational redundancy than a backed project with multiple maintainers.
The repository recorded no commits and no active maintainers in the last 3 months. The current release and longer release history provide some compensation, but this still raises near-term maintenance risk.
Composer is used for builds, but no security scanning tools were detected. This is a transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.5|^5.0.0-beta.1 | — | — |
pestphp/pest Version ^2.26|^3.0|^4.0 | — | — |
fakerphp/faker Version ^1.16 | — | — |
composer/semver Version ^3.4 | — | — |
mockery/mockery Version ^1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.