Its workflows have no audit findings, but all 11 action references are unpinned and one workflow grants top-level write access. A security policy is also absent, while repository tests, a substantial README, and a matching source repository provide useful transparency.
62%
Total Score
50
80
50
The package is less than 1 day old, with five releases arriving about 1 hour 16 minutes apart. Rapid initial releases show activity but provide almost no evidence of sustained maintenance.
No commits or active maintainers were recorded in the last 3 months, but the repository was pushed less than 1 day ago and the package itself is less than 1 day old, making the longer-window measure inconclusive.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented. This is a modest transparency gap for a tool intended to be used in development environments.
Version v0.1.4 is not a stable-major release, so its 0.x status signals an early-stage API and maturity profile rather than an established dependency.
The audit found no high-confidence workflow findings or untrusted checkout and script-injection paths. However, all 11 action references are unpinned and one workflow has top-level write permissions, creating avoidable maintenance and token-scope risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 | — | — |
symfony/finder Version ^7.0 | — | — |
symfony/console Version ^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.