Its documentation, licensing, and security process are clear. Workflow dependency pinning and an install-time script leave modest hygiene work, but the project has substantial maintenance capacity.
91%
Total Score
100
100
75
The package runs a post-autoload-dump install-time lifecycle script. Such scripts increase installation-time execution exposure, although this signal alone does not show harmful behavior.
All 14 workflows were analyzed successfully, with no untrusted checkout or script-injection findings, and 8 workflows use read-only permissions. However, all 28 analyzed action references are unpinned and a high-confidence low-severity finding reports an ad hoc package installation, so workflow hygiene merits caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.16 | — | — |
react/stream Version ^1.4 | — | — |
sebastian/diff Version ^4.0.6 || ^5.1.1 || ^6.0.2 || ^7.0 || ^8.0 || ^9.0 | — | — |
symfony/finder Version ^5.4.45 || ^6.4.24 || ^7.0 || ^8.0 | — | — |
composer/semver Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.