Workflow references are not pinned, and the repository lacks a security policy. It still has tests, release notes, a clear MIT license, and organization backing.
78%
Total Score
83
100
100
83
No commits and no active maintainers were recorded in the last three months. This conflicts with the recent releases, merges, and repository push, but still indicates a short-term maintenance-activity gap.
The repository has no security policy file. That is a transparency and vulnerability-reporting gap, although Dependabot provides some compensating security tooling.
All 17 action references are unpinned, which weakens build reproducibility, and the audit found a high-confidence bot-condition issue in the auto-merge workflow. The pull_request_target trigger has no untrusted checkout or script-injection sink, so this is a hygiene concern rather than a severe supply-chain finding.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nikic/php-parser Version ^5.5 | — | — |
webmozart/assert Version ^1.7 || ^2.1 | — | — |
phpdocumentor/type-resolver Version ^2.0 | — | — |
phpdocumentor/reflection-common Version ^2.1 | — | — |
phpdocumentor/reflection-docblock Version ^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.