Testing and release documentation are present, with three contributors active over the last three months. The workflow audit found no dangerous findings, though all 11 action references are unpinned and the repository lacks a security policy.
87%
Total Score
100
100
50
A post-autoload-dump install lifecycle script is present. This is worth noting because installation executes package code, but the signal provides no evidence that the script is unsafe.
No repository security policy was found. This is a minor transparency gap for a maintained library, but it is not evidence of unsafe code by itself.
All 4 workflows were analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 11 action references are unpinned, a reproducibility and supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
temporal/sdk Version ~2.17.0 | — | — |
symfony/process Version ^7.2 || ^8.0 | — | — |
spiral/roadrunner Version ^2025.1.5 | — | — |
illuminate/contracts Version ^11.0 || ^12.0 || ^13.0 | — | — |
spiral/roadrunner-cli Version ^2.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.