Named-entity recognition for PHP
68%
Total Score
caution
Usable with caveats: install-time downloads and unpinned workflow actions add supply-chain exposure.
The package runs post-install and post-update scripts, and its README says these scripts download a shared library; this adds install-time behavior and supply-chain exposure for consumers.
The repository had zero commits and zero active maintainers in the last three months, which weakens evidence of active maintenance even though a recent release and push show the project is not abandoned.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
Version v0.3.0 is not a stable major version, which signals a less mature compatibility commitment, although it is not a prerelease and recent releases contain no prerelease share.
All two analyzed workflow action references are unpinned, so they can change without a repository commit; the audit found no dangerous triggers, untrusted checkouts, script injection, or other flagged findings.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.