PHP library for matching installed packages against security advisories from Packagist, OSV and NVD
58%
Total Score
caution
Usable with caveats: this first release has no established maintenance record and all workflow actions are unpinned.
The package defines a post-install-cmd script, adding install-time behavior that deserves review beyond ordinary dependency loading.
This package is brand new, with only one release and no established release cadence, so its long-term maintenance is unproven.
The repository has no commits in the past three months, but it was created and pushed on the same day as this release, so this is limited evidence rather than clear abandonment.
Version 0.1.0 is an initial minor release rather than a stable major release, which increases API-change risk for adopters.
Both workflows were fully analyzed with no dangerous findings, but all 10 referenced actions are unpinned, leaving action versions exposed to unexpected changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
composer/semver Version ^3.4 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.