The repository is well documented, includes tests, and has a security policy. Its one-day history and single-maintainer ownership leave little evidence of long-term stability, while all 12 workflow actions are unpinned.
63%
Total Score
67
100
88
88
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not visibly supported by broader organizational backing.
The package is only 1 day old, despite 7 releases in that period; this shows active initial work but provides no evidence of sustained maintenance or release stability.
One contributor made all 92 commits in the last 3 months, leaving maintenance highly dependent on a single person.
Composer build tooling is present, but no repository security-scanning tools were detected. The package itself includes security-oriented checks, which partly offsets this project-level gap.
Both workflows were fully analyzed with no reported audit findings or untrusted checkouts, and neither uses broad top-level write permissions. However, all 12 analyzed action references are unpinned, weakening build reproducibility and action-integrity protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^6.0|^7.0 | — | — |
symfony/process Version ^6.0|^7.0 | — | — |
nikic/php-parser Version ^5.0 | — | — |
illuminate/console Version ^9.0|^10.0|^11.0|^12.0 | — | — |
illuminate/support Version ^9.0|^10.0|^11.0|^12.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.