The repository is clearly owned by an organization and includes tests, documentation, and release notes. Its workflows use unpinned actions and inherit secrets, while the project has no security policy; these are manageable but meaningful hygiene gaps.
78%
Total Score
100
100
89
67
This is the first release, published less than an hour ago, so there is no long-term maintenance record yet. The repository was pushed immediately before publication, which partly offsets the limited history.
Composer build tooling is present, but no security scanning tool was detected in the repository. This is a modest transparency and maintenance gap rather than a release blocker.
The repository has no security policy, leaving the process for reporting and handling vulnerabilities undocumented.
Both workflows were analyzed and use read-only permissions, with no untrusted checkout or script-injection findings. However, all three action references are unpinned and high-confidence secrets-inherit findings appear in the pull-request guardrail workflow, so CI supply-chain hygiene is a caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
pimcore/pimcore Version ^2026.2 | — | — |
guzzlehttp/guzzle Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.