It includes tests, a README, an MIT license, and organization backing. The CI workflow leaves all 10 actions unpinned and the repository has no security policy, increasing maintenance and build-integrity concerns.
66%
Total Score
100
50
83
50
The package declares 12 runtime dependencies, including several project-specific bundles, which increases dependency and maintenance surface for consumers.
The package has only two releases, with the latest published about 11 months ago; this limited history and long pause leave maintenance continuity uncertain.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The linked repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
The single workflow is fully analyzed and scopes permissions at job level, with no dangerous triggers or audit findings. However, all 10 referenced actions are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2 | — | — |
symfony/validator Version ^7.2 | — | — |
symfony/serializer Version ^7.2 | — | — |
doctrine/collections Version ^1.5 | — | — |
php-solution/std-lib Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.