Documentation and project hygiene are solid. The young 0.x project and small contributor base warrant monitoring, while unpinned workflow actions add avoidable build risk.
79%
Total Score
83
93
100
Two contributors are active, and the organization-backed project can hand work off, partly reducing the risk from one contributor making about 71% of recent commits.
v0.13.0 is not marked prerelease, but the package remains below a stable 1.0 major version, so its API and behavior may still change substantially.
The workflows were fully analyzed with no reported dangerous sinks or audit findings, but all 15 action references are unpinned and one workflow grants top-level write access, leaving avoidable build-integrity and permission concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
nesbot/carbon Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
symfony/console Version ^7.0 | — | — |
nikic/php-parser Version ^5.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.