The project is actively maintained, with 49 commits in three months, recent release notes, tests, and a clear license. Workflow references are not pinned and the repository has no security policy, leaving avoidable supply-chain and reporting gaps.
78%
Total Score
100
94
67
Composer is used for builds, but no security-scanning tooling was detected. This is a modest transparency gap rather than evidence of unsafe code.
The repository has no published security policy, leaving vulnerability reporting and response expectations unclear for a web framework.
The single workflow was fully analyzed with no untrusted checkouts or script injection, but all 38 action references are unpinned and four high-confidence unpinned-image findings were reported. This leaves avoidable build reproducibility and action supply-chain risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psy/psysh Version ^0 | — | — |
erusev/parsedown Version ^1 | — | — |
mrclay/jsmin-php Version ^2 | — | — |
bower-asset/jquery Version ^3 | — | — |
bower-asset/tinymce Version ^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.