The package includes a clear README, release notes, security policy, and security scanning. Install-time scripts, an uncovered license mismatch, and unpinned workflow actions warrant attention, but recent project activity is strong.
86%
Total Score
100
94
67
The artifact and repository contain license files, but the detected CC-BY-SA-4.0 and MIT licenses are broader than the manifest's MIT declaration. That mismatch reduces licensing clarity for consumers.
The package runs post-install and post-update Composer scripts. These add installation-time execution and therefore require more trust than a package without lifecycle scripts.
All six workflows were analyzed without failed files or dangerous audit findings, and no untrusted checkout or script-injection patterns were found. However, all 13 analyzed action references are unpinned and one workflow grants top-level write permissions, creating a workflow-hygiene concern.
| Title | Versions | Severity |
|---|---|---|
CVE-2025-63644 ph7software/ph7builder is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 0.0.0 - 17.9.1. | 0.0.0 - 17.9.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
twilio/sdk Version ^8.0 | — | — |
geoip2/geoip2 Version ^3.3 | — | — |
ph-7/datatype Version ^1.0 | — | — |
fakerphp/faker Version ^1.24 | — | — |
symfony/mailer Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.