Declarative workflow engine for PHP with automatic dependency resolution, sync/async job execution, and type-safe response chaining.
78%
Total Score
67
100
100
50
All three recent commits came from one contributor. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
Only three commits were made in the last three months, which is modest activity, though the frequent registry releases show the project is not abandoned.
The repository has no published security policy, leaving vulnerability-reporting expectations unclear despite its security scanning tooling.
Both workflows were analyzed without high-confidence audit findings or dangerous triggers, but all seven action references are unpinned, weakening build reproducibility. The absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
amphp/amp Version ^3.1 | — | — |
chevere/regex Version ^1.0.2 | — | — |
chevere/action Version ^3.0.2 | — | — |
chevere/caller Version ^1.0.0 | — | — |
chevere/container Version ^1.0.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.