It includes a substantial README, release notes, repository tests, and a matching source project. Recent activity is limited to one contributor, while all 11 workflow actions are unpinned.
76%
Total Score
67
100
94
50
The package uses a post-root-package-install script, adding install-time behavior that deserves attention, though this alone is not a severe concern.
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not obviously offset by broader project backing.
All four recent commits came from one contributor, leaving maintenance dependent on a single active person.
Composer build tooling is present, but no repository security-scanning tool was detected, leaving a modest transparency and monitoring gap.
All four workflows were analyzed without reported findings or untrusted checkout/script-injection paths. However, all 11 action references are unpinned and one workflow has top-level write permissions, creating workflow hygiene and update-integrity concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0|^7.0|^8.0 | — | — |
league/flysystem Version ^3.0 | — | — |
vlucas/phpdotenv Version ^5.0 | — | — |
doctrine/inflector Version ^2.0 | — | — |
cable8mm/array-flatten Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.