Extensive documentation and tests make integration clearer, while build and security tooling add useful discipline. The organization-backed project has multiple recent contributors; unpinned workflow actions and the missing security policy are the main remaining concerns.
88%
Total Score
100
100
50
No security policy is published in the repository, which reduces transparency about reporting and handling vulnerabilities. The existing Sonar scanning provides some compensation but does not replace a policy.
The single workflow was fully analyzed, has job-level permission scoping, and has no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 6 action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
guzzlehttp/psr7 Version ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.4.5 | — | — |
symfony/serializer Version ~7.0.0 | — | — |
phpstan/phpdoc-parser Version * | — | — |
symfony/property-info Version ~7.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.