Documentation, tests, licensing, and a GitHub release make the package transparent and straightforward to evaluate. The workflow uses unpinned actions and the repository lacks a security policy, so ongoing operational maturity is limited.
62%
Total Score
75
100
88
67
The package was published today and has only one release, so there is no demonstrated long-term maintenance or release history yet.
One contributor made all 23 recent commits, creating a significant continuity risk if that maintainer becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security coverage unclear.
The repository has no security policy, which makes vulnerability reporting and response expectations less transparent.
The single workflow was fully analyzed with no unsafe-trigger or injection findings, but both action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/guzzle Version ^7.15 | — | — |
symfony/dependency-injection Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.