The package has clear documentation, release notes, a recognized license, and an active organizational home. Workflow credential sharing and unpinned actions deserve attention, while recent work comes from one contributor.
68%
Total Score
88
100
94
75
One contributor made all 5 recent commits, leaving maintenance concentrated in a single person. Organizational ownership provides some handoff capacity, but it does not remove the continuity risk.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest gap in automated supply-chain hygiene.
The repository has no security policy, so users lack a documented channel and process for reporting vulnerabilities.
All three workflows were analyzed without failures and have no untrusted checkout or script-injection findings, but all 6 action references are unpinned and two high-confidence medium-severity secrets-inherit findings expose credentials more broadly than necessary.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
innmind/url Version ~5.0 | — | — |
innmind/http Version ~9.0 | — | — |
innmind/immutable Version ~6.0 | — | — |
innmind/url-template Version ~4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.