Adoption should account for automation hygiene and continuity of individual ownership. The repository is organization-backed, actively releasing, tested, and covered by a security policy, but all recent commits come from one contributor and every action reference is unpinned.
76%
Total Score
88
100
100
75
A post-autoload-dump install-time script runs during Composer operations, adding execution during installation; this is a modest supply-chain and reproducibility concern without evidence of unsafe behavior.
One contributor made all 34 commits in the last three months, giving the project a bus-factor weakness despite the repository's organizational ownership.
All eight workflows were analyzed without high-confidence audit findings, and six use read-only permissions. However, all 36 analyzed action references are unpinned and one workflow has top-level write permissions, creating a workflow-reproducibility and token-scope caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
orchestra/sidekick Version ~1.1.23|~1.2.20 | — | — |
symfony/polyfill-php84 Version ^1.34.0 | — | — |
symfony/deprecation-contracts Version ^2.5|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.