Core module for Altis
88%
Total Score
100
50
100
63
One workflow uses pull_request_target, which warrants review because it can run with elevated repository context; however, no untrusted checkouts or script-injection patterns were detected.
The release has five runtime dependencies, including the PHP and Composer interfaces plus AWS SDK and analytics libraries; this is a meaningful but not unusually broad dependency surface.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear for consumers and maintainers.
Three of four workflows lack top-level permission declarations, and one backport workflow grants top-level write access; this is weaker workflow hardening than preferred.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
aws/aws-sdk-php Version ^3.393.5 | — | — |
composer/installers Version ^1.12 || ^2.3.0 | — | — |
segmentio/analytics-php Version ~3.8.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.