The package has clear licensing, tests, release notes, and a broad contributor base. Workflow references are unpinned, and no security policy or scanning tools are reported, so provenance controls deserve attention.
84%
Total Score
100
50
94
50
The package declares 64 runtime dependencies, including broad framework and service integrations; that increases update and compatibility surface compared with a small focused library.
A post-install-cmd script runs during installation, adding execution during dependency setup and therefore some additional supply-chain exposure.
The project uses Make and Composer, but no security-scanning tools were detected, leaving a repository security-process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response procedures.
All three workflows were analyzed without reported audit findings or dangerous trigger sinks, but all 23 action references are unpinned; the workflows also omit top-level permissions blocks, which is acceptable on its own but less explicit.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/cache Version ^3.0 | — | — |
twig/twig Version ^3.27 | — | — |
spatie/url Version ^2.2 | — | — |
nette/utils Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.