Healthy and reasonable to depend on. It has frequent releases, recent commits, tests, an active organization-backed repository, and no deprecation or archive status; maintenance is somewhat concentrated in one contributor and its workflow permissions are not explicitly restricted.
86%
Total Score
90
100
94
80
One workflow uses pull_request_target, which deserves review because it can run with elevated repository context, but there is no detected untrusted checkout or script injection.
One contributor made 87.5% of the 16 recent commits, creating concentration risk; the second active contributor and organization ownership partly compensate, so this is a manageable caution rather than a severe abandonment signal.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency gap rather than evidence that the package is unsafe.
The analyzed workflow has no top-level token permissions declaration. No write permissions were explicitly requested, but the absence of a restrictive declaration leaves unnecessary ambiguity.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-31485 api-platform/graphql is vulnerable to Incorrect Behavior Order in versions 0.0.0 - 3.4.17, 4.0.0-alpha.1 - 4.0.22 and 4.1.0-alpha.1 - 4.1.5. | 0.0.0 - 3.4.174.0.0-alpha.1 - 4.0.224.1.0-alpha.1 - 4.1.5 | High |
CVE-2025-31481 api-platform/graphql is vulnerable to Incorrect Authorization in versions 4.0.0-alpha.1 - 4.0.22, 0.0.0 - 3.4.17 and 4.1.0-alpha.1 - 4.1.5. | 0.0.0 - 3.4.174.0.0-alpha.1 - 4.0.224.1.0-alpha.1 - 4.1.5 | High |
| Dependency | Last Release | Score |
|---|---|---|
symfony/type-info Version ^7.4 || ^8.0 | — | — |
api-platform/state Version ^5.0 | — | — |
symfony/serializer Version ^7.4 || ^8.0 | — | — |
webonyx/graphql-php Version ^15.0 | — | — |
api-platform/metadata Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.