King native PHP extension packaged for PIE
68%
Total Score
caution
Usable with caveats: the release workflow has high-confidence injection findings and entirely unpinned actions.
All three workflows were analyzed, but all 75 action references are unpinned. The release workflow also has a high-confidence script-injection finding and uses trusted publishing; these create material CI and release-chain hygiene concerns, although no untrusted checkout or dangerous trigger was reported.
One contributor made about 97.7% of the 443 recent commits, creating concentration risk. The organization-owned project and a second active contributor partly compensate, but the maintenance base remains thin.
The project uses Make and Composer, but no security-scanning tooling was detected, leaving a meaningful security-process gap for a native extension.
The repository has no published security policy, reducing transparency for reporting and handling vulnerabilities.
This release is a prerelease, and 87.5% of recent releases are prereleases, so consumers should expect a less settled API and more upgrade risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.