The package includes tests, documentation, and a clear MIT license, while its repository matches the package and is organization-backed. The unpinned workflow actions and lack of a security policy leave avoidable maintenance and supply-chain hygiene gaps.
58%
Total Score
75
100
88
83
This is the package's only release, published 203 days ago, with no subsequent release activity. That provides limited evidence of ongoing maintenance for a security-focused package.
The repository recorded 0 commits and 0 active maintainers during the last 3 months, consistent with the one-release history and increasing abandonment risk.
Composer build tooling is present, but no security-scanning tooling was detected. This is a modest gap rather than a severe risk because the package has tests and a defined source tree.
The repository has no security policy, which is a meaningful transparency gap for a package whose purpose is scanning security vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, both action references are unpinned, leaving weaker build reproducibility and action-integrity controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^6.0|^7.0|^8.0 | — | — |
illuminate/support Version ^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.