The repository includes tests, a clear README, recent releases, and dependency scanning. Workflow actions are unpinned and no security policy is published, while recent commits come from one contributor.
78%
Total Score
50
100
100
75
All two recent commits came from one contributor, leaving maintenance capacity concentrated and increasing abandonment risk if that contributor stops.
The repository recorded two commits in the last three months, indicating some ongoing maintenance, though activity is light.
The repository has no published security policy, which limits guidance for reporting and handling vulnerabilities.
The sole workflow was fully analyzed with no audit findings or untrusted execution paths, but all six action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
friendsofphp/php-cs-fixer Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.