The project has six active contributors, frequent releases, tests, and release notes. Organization backing offsets the single registry publisher and concentrated commits, but workflow hygiene still warrants care.
72%
Total Score
100
100
83
75
The repository has only 7 stars and no forks, indicating limited adoption, but popularity is supporting evidence and does not outweigh the strong maintenance signals.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and defensive-hygiene gap.
The repository has no security policy, leaving vulnerability reporting and handling expectations undocumented.
This release is not a prerelease, although the package remains below a stable major version, so compatibility expectations may be less settled.
All five workflows were analyzed without untrusted triggers or script-injection sinks, but 9 of 12 action references are unpinned. A high-confidence template-injection finding in the release workflow is a meaningful release-process hygiene concern; the low-confidence cache finding is only minor.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^1 || ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.