Tests, a changelog, a security policy, and a matching repository improve transparency. Workflow references are all unpinned, and recent activity is light, so pin version 2.18.5 and watch maintenance.
82%
Total Score
83
100
94
100
Two commits from two active maintainers in the last three months show recent activity, though the volume is light for a mature project.
Composer build tooling is present, but no security scanning tool was detected; this is a modest transparency gap rather than a dependency-blocking concern.
The sole workflow was fully analyzed with no untrusted checkout, script injection, or audit findings, but all five action references are unpinned, leaving them exposed to upstream changes.
| Title | Versions | Severity |
|---|---|---|
CVE-2017-16880 filp/whoops is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 2.1.13. | 0.0.0 - 2.1.13 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0.1 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.