The package includes a substantial README and tests, and the repository has 55 commits from two contributors in the last three months. Its workflows install an unlocked package and leave all six actions unpinned; the low-confidence cache warning is only hygiene.
78%
Total Score
67
100
94
75
The repository is owned by a user account rather than an organization, so the small contributor base has less formal project-backing compensation.
Two contributors are active, but the leading contributor made about 67% of recent commits, leaving some concentration risk despite meaningful secondary participation.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and assurance gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
All six analyzed action references are unpinned, and the publish workflow installs a package outside a lockfile; these weaken reproducibility, while the low-confidence cache-poisoning finding is hygiene rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
kematjaya/crud-maker-core Version @dev | — | — |
kematjaya/crud-maker-api-bundle Version @dev | — | — |
kematjaya/crud-maker-twig-bundle Version @dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.