Parse, verify and sign signed notes — the transparency-log / Go sumdb format used by Sigstore Rekor checkpoints — in PHP
68%
Total Score
67
100
94
75
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
The package is young at 77 days with three releases and a median interval of about 39 days. Recent publishing is active, but the short history provides limited evidence of long-term maintenance.
All 10 recent commits came from one contributor, so maintenance depends heavily on a single person and has limited handoff capacity.
All workflows were analyzed successfully, but the audit found a high-confidence bot-conditions issue in a pull_request_target workflow; that workflow also has top-level write permissions. Two of five action references are unpinned, a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
k2gl/dsse Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.