The README, tests, and release notes make the tool easier to evaluate, while read-only workflow permissions limit CI exposure. Missing security scanning and unpinned Actions leave avoidable maintenance and build-integrity gaps.
62%
Total Score
50
83
50
This package has only one release, published about 179 days ago, so there is little evidence of an established release or maintenance pattern.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance for a recently published tool.
Composer and Box provide build tooling, but the repository reports no security-scanning tools, leaving a meaningful transparency and maintenance gap.
No security policy is present, so users have no documented vulnerability-reporting path or stated security response process.
All 2 analyzed action references are unpinned, creating avoidable build-integrity risk. The workflow uses read-only permissions and has no untrusted checkout or script-injection findings, which limits the exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0|^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
phpstan/phpdoc-parser Version ^1.0 | — | — |
symfony/dependency-injection Version ^6.0|^7.0 | — | — |
composer-unused/symbol-parser Version ^0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.