The package is clearly documented and has a recent release with published notes. Its organization-backed repository is active, but one person handles all recent commits and workflow actions are entirely unpinned.
70%
Total Score
83
100
100
75
All 142 commits in the last three months came from one contributor, leaving no demonstrated recent handoff capacity. Organization ownership provides some backing, but no second active contributor is shown.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities. This is a documentation gap rather than evidence of unsafe code.
Both workflows were analyzed with no injection or high-severity findings, but all 6 action references are unpinned, so builds can follow changed action code over time.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^11.5 || ^12.5 || ^13.3 | — | — |
nikic/php-parser Version ^5.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.