Documentation and project safeguards are in place. Recent work is concentrated in one contributor, and all 20 workflow actions are unpinned.
78%
Total Score
67
94
100
All six recent commits came from one contributor, creating a meaningful short-term concentration risk. Organization ownership provides some backing, but no second recent contributor is shown.
Six commits were made in the last three months, so activity continues, but only one maintainer was active during that period.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and assurance gap.
All eight workflows were analyzed with no high-confidence audit findings or untrusted checkout and script-injection patterns. However, all 20 action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version 1 - 3 | — | — |
spiral/core Version ^2.8 || ^3.0 | — | — |
spiral/pagination Version ^2.8 || ^3.0 | — | — |
symfony/polyfill-php83 Version ^1.28 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.