Clear licensing, tests, release notes, and security tooling improve day-to-day confidence. Pin reviewed workflow revisions before relying on its CI supply chain.
86%
Total Score
100
100
100
67
The repository has no published security policy, leaving vulnerability-reporting expectations less transparent despite its other security tooling.
All three workflows were analyzed successfully, with no detected injection, untrusted-checkout, or high-severity findings; however, all 13 action references are unpinned, which is a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
bedita/i18n Version ^6.0.0 | — | — |
cakephp/cakephp Version ^5.3 | — | — |
bedita/web-tools Version ^6.0.0 | — | — |
league/flysystem Version ^3.16 | — | — |
josegonzalez/dotenv Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.