The package is clearly licensed, documented for consumers, and free of install-time scripts. Keep an eye on its small repository footprint and limited security tooling as the project evolves.
68%
Total Score
67
100
93
83
One contributor made all 3 commits in the last 3 months, concentrating recent maintenance. Organization ownership provides some handoff capacity, but the observed activity still leaves a thin active contributor base.
The repository recorded 3 commits in the last 3 months, showing recent activity but at a modest pace. This is sufficient for a caution rather than an abandonment finding because release activity remains frequent.
Composer is used for builds, but no security-scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not evidence of unsafe code by itself.
The sole workflow uses pull_request_target and has one unpinned action, creating a hygiene concern. However, the audit found no untrusted checkout, script injection, excessive top-level write permissions, or other findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
php-flasher/flasher-notyf Version ^2.6.3 | — | — |
php-flasher/flasher-symfony Version ^2.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.