MIT licensing and a clear README support straightforward use. Repository tests, recent release notes, and organization backing are reassuring, while workflow pinning and security-policy gaps warrant routine review.
86%
Total Score
100
100
94
67
The project uses Composer and Make, but no security-scanning tools were detected, leaving a modest transparency gap.
No repository security policy was found, which makes vulnerability-reporting expectations less clear for users and maintainers.
All 16 analyzed action references are unpinned, and one of two workflows has top-level write permissions; the audit found no untrusted checkouts, injection sinks, or other findings, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpunit/phpunit Version ^13.3.4 | — | — |
symfony/console Version ^7.4.8 || ^8.1.7 | — | — |
symfony/process Version ^7.4.8 || ^8.1.7 | — | — |
phpunit/php-timer Version ^9 | — | — |
sebastian/environment Version ^9.3.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.