Documentation, licensing, tests, and security policy are in place, while the single organization-backed maintainer model limits independent resilience. Pin this release and review the workflow images before adoption.
70%
Total Score
75
100
100
67
The package runs post-install and post-update Composer scripts. These add installation-time execution surface and warrant review, although the signal does not show that the scripts are harmful.
There were no commits and no active maintainers in the last three months. This is a meaningful maintenance warning, but it is partly offset by a release published during the same period.
All four workflows were analyzed without failures and have no untrusted checkout or script-injection findings, but the audit found two high-confidence unpinned container images and all eight action references are unpinned. Those workflow supply-chain controls are a genuine hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ray/di Version ^2.13.2 | — | — |
ray/aop Version ^2.10.4 | — | — |
psr/cache Version ^1.0.1 || ^2.0 || ^3.0 | — | — |
symfony/cache Version ^6.0 || ^7.2 | — | — |
psr/simple-cache Version ^1.0 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.