The package includes a license, security policy, active automation, and a recent release with documented notes. Install-time scripts and workflow issues add maintenance and build-integrity concerns, so pin this version while watching for renewed commits.
65%
Total Score
50
100
83
The package runs post-install and post-update Composer scripts. These are an additional installation-time execution surface and warrant caution even though the package is explicitly a PHP template.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push and release show some activity, but the lack of commits lowers confidence in ongoing maintenance.
All seven workflows were analyzed, but all 17 action references are unpinned, two workflows grant top-level write permissions, and a high-confidence bot-conditions finding affects the Dependabot auto-merge workflow. A low-confidence-impact adhoc package installation finding adds minor hygiene concern; no untrusted checkout or script injection was found.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.