Clear documentation and a security policy make adoption easier. Its small, young project history leaves less evidence about long-term continuity.
87%
Total Score
100
88
100
The package is only 51 days old with three releases, all within a very short period, so it has limited long-term maintenance history despite recent release activity.
Version 0.1.2 is not a stable major release, which indicates an immature API and greater potential for compatibility changes, although it is not marked as a prerelease.
All three workflows were analyzed, all use read-only permissions, and all 38 action references are pinned. High-confidence findings include two adhoc package installs and trusted publishing; the low-confidence cache findings are hygiene concerns rather than strong evidence of risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
laravel/pint Version ^1.27 | — | — |
rector/rector Version ^2.1.3 | — | — |
phpstan/phpstan Version ^2.1.22 | — | — |
phpstan/extension-installer Version ^1.4 | — | — |
tomasvotruba/cognitive-complexity Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.