Its focused artifact is clearly licensed and documented, and the organization-backed repository matches the package. A small dependency set and no dangerous workflow findings provide useful support despite the remaining maintenance and workflow hygiene concerns.
67%
Total Score
100
100
81
83
The package has 47 releases since 2019, but none in the last 12 months and the latest registry release was about 19 months ago. This indicates slowed release maintenance, although the repository was pushed more recently.
Composer build tooling is present, but no security scanning tools were detected. For a small PHP extension this is a minor repository hygiene gap, not evidence that the release is unsafe.
The repository has no security policy. That reduces vulnerability-reporting transparency, though the package is small and other repository metadata is available.
Version 0.7.0 is not a stable major version, but it is not marked as a prerelease and recent releases have not been prereleases. This is a modest maturity limitation rather than a severe concern.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 7 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2 | — | — |
phpstan/extension-installer Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.