Its MIT licensing and clean install behavior reduce adoption friction. The repository lacks security scanning, and its only action uses an unpinned reference; these are hygiene concerns rather than blockers.
76%
Total Score
75
92
67
No commits and no active maintainers were recorded in the last 3 months, which is a maintenance warning, although the very recent release and repository push provide compensating evidence.
Composer is used for builds, but no repository security-scanning tool was detected; this is a transparency and hygiene gap rather than evidence of unsafe code.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures undocumented.
The only workflow uses a pull_request_target trigger without an untrusted checkout or script-injection sink, but its sole action reference is unpinned; the audit otherwise found no security findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^7.4.0 || ^8.0.0 | — | — |
guzzlehttp/psr7 Version ^2.9 || ^3.0 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
guzzlehttp/guzzle Version ^7.8.2 || ^8.0 | — | — |
fruitcake/php-cors Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.