Clear documentation, tests, release notes, and a security policy make the project easy to assess. Organization backing and several active contributors reduce the risk from concentrated recent commit activity, though most recent commits come from one person.
84%
Total Score
100
100
75
The package runs post-autoload-dump and post-root-package-install scripts during Composer operations; these add install-time behavior that merits awareness, but the signal alone does not show unsafe commands.
All five workflows were analyzed with no audit findings, no untrusted checkout or script-injection paths, and no high or medium severity issues. However, all 13 action references are unpinned and three workflows grant top-level write permissions, which are hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/csv Version 9.* | — | — |
genkgo/camt Version >=2.10.1 | — | — |
ramsey/uuid Version ^4.9 | — | — |
spatie/enum Version ^3.10 | — | — |
firebase/php-jwt Version ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.