The project presents a clear integration path for PHP applications. One active contributor carries all recent commits, and all 15 workflow actions are unpinned, creating maintainability and build-integrity concerns despite strong release documentation.
82%
Total Score
83
100
94
100
All 53 recent commits came from one contributor, so maintenance depends heavily on a single individual even though the repository is organization-owned.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
Both workflows were analyzed without audit findings or untrusted triggers, and one uses read-only permissions. However, all 15 analyzed action references are unpinned, which weakens build reproducibility and action supply-chain integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 ||^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.