A clear README, MIT licensing, and security scanning improve adoption confidence. Recent releases and two active contributors are reassuring, though most recent commits come from one person and all workflow actions are unpinned.
82%
Total Score
83
100
75
Two contributors were active in the last 3 months, but the leading contributor made 5 of 6 commits. This leaves meaningful dependence on one maintainer and lowers resilience.
No repository security policy was found. For a maintained developer tool, this is a transparency gap, although recent releases and security scanning provide partial compensation.
The single workflow was fully audited with no untrusted checkouts, injection findings, or high-confidence audit issues, and it avoids top-level write permissions. However, all 8 action references are unpinned, creating a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/framework Version 6.*|7.*|8.*|9.*|10.*|11.*|12.*|13.* | — | — |
imanghafoori/composer-json Version ^2.1.0 | — | — |
composer/class-map-generator Version ^1.0.0 | — | — |
jetbrains/phpstorm-attributes Version 1.* | — | — |
imanghafoori/php-search-replace Version ^1.1.16 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.