The source repository has tests, release notes, explicit licensing, and a clear package structure. No install-time scripts or deprecation notice reduce adoption risk, while missing security tooling and a security policy leave some transparency gaps.
70%
Total Score
75
100
88
67
The package is mature, with 20 releases since December 2020, but only one release in the last 12 months; this suggests a slower maintenance pace.
There were no commits or active maintainers in the three months measured, which is a concrete sign of currently quiet development; the recent release partly offsets but does not remove this concern.
Composer is used for builds, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less transparent.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, so their contents can change unexpectedly.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/filesystem Version ^4.4.17|^5.0|^6.0|^7.0|^8.0 | — | — |
laminas/laminas-code Version ~3.4.1|^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.