Clear documentation, regular releases, and a security policy support continued use. All eight workflow actions are unpinned, and recent commits come from one contributor.
82%
Total Score
83
100
67
The package runs post-install and post-update Composer scripts, which expand installation-time execution beyond ordinary dependency loading. No script behavior is provided to compensate for that added execution surface.
One contributor made all four commits in the last three months, concentrating recent maintenance in a single person. Organization ownership provides some handoff capacity, but no second recent contributor is shown.
All four workflows were analyzed successfully with no untrusted checkouts, script injections, or audit findings. However, all eight action references are unpinned, leaving their exact revisions mutable and creating a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.16.1 || ^2.17 || ^2.18 || ^2.19 | — | — |
psr/log Version ^1.1 || ^2.0 || ^3.0 | — | — |
ray/aop Version ^2.16.2 || ^2.17 || ^2.18 || ^2.19 | — | — |
aura/sql Version ^5.0 || ^6.0 | — | — |
aura/sqlquery Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.