Utility for OpenApi 2/3 generators
86%
Total Score
healthy
Regular releases and active six-contributor development support this maintained package; workflow pinning and security-policy gaps remain.
The project uses Composer build tooling, but no security-scanning tool was detected; this is a modest transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The single workflow uses a pull_request_target trigger without an untrusted checkout or script injection, but its one action is unpinned and the audit found no top-level permissions block. The unpinned reference is a workflow hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/string Version ^7.0 || ^8.0 | — | — |
symfony/console Version ^7.0 || ^8.0 | — | — |
symfony/filesystem Version ^7.0 || ^8.0 | — | — |
symfony/var-dumper Version ^7.0 || ^8.0 | — | — |
jane-php/json-schema Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.