Collection of files for use in CI
68%
Total Score
caution
Usable with caveats—one-person maintenance and all workflow actions unpinned weaken confidence.
The package declares five runtime dependencies, including CI and analysis tools; that is substantial for a collection of CI files but consistent with its stated purpose.
The repository is organization-owned, which provides some handoff capacity, but one contributor made 100% of recent commits and no second contributor was active.
Composer is used for builds, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so vulnerability reporting and response expectations are not documented.
All 28 workflows were analyzed without failures and have no untrusted checkouts or script-injection findings. However, all 12 analyzed action references are unpinned, and high-confidence template-injection findings are present; template injection alone is workflow hygiene, while the complete audit limits uncertainty.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
rector/rector Version ^2 | — | — |
phpstan/phpstan Version <2.2.6||^2.2.7 | — | — |
phpunit/phpunit Version ^9.5 || ^10 || ^11 | — | — |
friendsofphp/php-cs-fixer Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.