The project includes tests, a changelog, a security policy, and fully pinned action references. Contributor activity is concentrated, while several high-confidence workflow findings warrant tightening around automation permissions and conditions.
79%
Total Score
83
100
75
A post-autoload-dump install script runs during installation. This adds execution surface for consumers, although the signal provides no evidence that the script is harmful.
One contributor made 88% of the recent commits, creating concentration risk, though a second contributor remains active and the repository is owned by an organization that can provide handoff capacity.
All four workflows were analyzed, and all 37 action references are pinned, but one workflow grants top-level write access and high-confidence findings report blanket GitHub App permissions, spoofable bot conditions, and an unpinned container image.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
ramsey/uuid Version ^4.0 | — | — |
nesbot/carbon Version ^2.0|^3.0 | — | — |
monolog/monolog Version ^3.6 | — | — |
symfony/console Version ^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.