Set of common PHPUnit custom assertions.
78%
Total Score
healthy
Healthy, backed by a current release and an unarchived repository.
The package uses a post-autoload-dump install-time script. This is an additional installation behavior to understand, but the signal provides no evidence that it is harmful or unusually broad.
All one commit in the last three months came from one contributor, giving the recent activity a very concentrated bus factor. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest visibility gap rather than evidence of unsafe maintenance.
Version 0.15.0 is not a prerelease and recent releases are stable, though the package remains below a stable major version and may allow more compatibility changes.
Both workflows were fully analyzed with no dangerous audit findings or untrusted-trigger sinks, and neither grants top-level write permissions. However, all 4 referenced actions are unpinned, which weakens build reproducibility and action supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^9.1 || ^10.0 || ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.