The repository remains active with two contributors, and the package includes clear usage documentation and release notes. Workflow pinning and security-policy gaps need attention before broad adoption.
68%
Total Score
100
88
75
The manifest declares a proprietary license, so the release is licensed, though its terms may restrict use compared with a permissive open-source license.
The package has 72 releases since 2018, but none in the last 12 months and its latest registry release was over a year ago. Recent repository commits partly offset the registry inactivity, but release continuity remains a concern.
No repository security policy was found, leaving vulnerability-reporting expectations and disclosure procedures undocumented.
All 24 analyzed action references are unpinned, and the audit found one high-confidence template-injection issue. No untrusted checkout or script-injection trigger was reported, so these are workflow-hygiene concerns rather than a severe standalone risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.0 | — | — |
phpstan/phpstan Version ^2.0 | — | — |
webmozart/assert Version ^1.11 | — | — |
phpstan/phpstan-nette Version ^2.0 | — | — |
phpstan/phpstan-mockery Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.