The project has recent releases, active commits from two contributors, and a tested source repository. Its single workflow leaves action references unpinned and has no security policy, so maintenance transparency is not ideal.
82%
Total Score
100
100
89
83
The repository has zero stars, forks, and watchers, offering no adoption evidence. This is supporting evidence only and does not outweigh the observed release and maintenance activity.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest supply-chain hygiene gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, which weakens build reproducibility and action-integrity controls.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
phpstan/phpstan Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.