The project is permissively licensed, has repository tests, and publishes release notes for this version. Organization backing and multiple recent contributors support continuity, though workflow references are all unpinned and no security policy or scanning tool was found.
82%
Total Score
100
100
86
67
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance-process gap.
The repository has no security policy, so vulnerability reporting and response expectations are less transparent to consumers.
Version 0.6.0 is not yet on a stable major version, which leaves more compatibility uncertainty, but it is a regular stable release rather than a prerelease and recent prereleases are absent.
The single workflow uses read-only permissions and has no untrusted checkouts, injection sinks, or audit findings, but all 8 action references are unpinned, reducing build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2.6.2 | — | — |
webmozart/assert Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.