The repository has tests, a changelog, security guidance, and active static analysis. Three workflow actions are unpinned and most recent work comes from two contributors, so keep normal dependency and CI review in place.
86%
Total Score
83
100
100
75
The package defines post-install and post-update scripts, which expand installation behavior beyond file extraction and deserve review when integrating the dependency.
Two contributors were active, but the leading contributor made about 69% of recent commits. This is some concentration, offset by the second contributor's 31% share.
The workflow audit analyzed all workflows, found read-only permissions, no untrusted checkouts or injection sinks, and no audit findings. However, all 3 of 3 action references are unpinned, leaving avoidable CI supply-chain drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
danog/php-rtc-exception Version ^1.1.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.