Two active contributors made 172 commits in three months, and the package includes tests, release notes, and dependency scanning. GitHub Actions still need tighter controls: all 13 actions are unpinned, one high-confidence bot-condition issue was found, and no security policy is published.
79%
Total Score
100
100
50
The package runs post-autoload-dump and post-update-cmd scripts, which can add install-time behavior and deserve review, though these hooks are consistent with a Composer package that integrates checks into project updates.
No SECURITY.md or other security policy was found, reducing transparency for vulnerability reporting even though dependency scanning is enabled.
The audit analyzed all five workflows without failures, but all 13 action references are unpinned and it found one high-confidence bot-condition issue; top-level write permissions also appear in two workflows, without an untrusted checkout or script-injection path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 || ^8.0 | — | — |
nesbot/carbon Version ^3.0 | — | — |
rector/rector Version ^2.5.8 | — | — |
symfony/finder Version ^7.4 || ^8.0 | — | — |
composer/semver Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.