All three workflow actions are unpinned, and the repository has no security policy or automated security scanning. Tests, release notes, licensing, and organization backing provide useful transparency, but issue and contributor activity have recently stalled.
67%
Total Score
67
100
94
75
There were zero commits and zero active maintainers in the last three months. Although the package has recent releases, this is direct evidence that source maintenance may be slowing.
The repository has 16 open issues and one open pull request, with no new or closed issues or merged pull requests in the last month. This suggests limited recent issue handling.
Composer is used for the build, but no security scanning tools were detected. That is a modest transparency and maintenance gap for a dependency published to a registry.
The repository has no security policy, leaving no documented route for reporting vulnerabilities or explaining security response expectations.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all three action references are unpinned, which leaves build automation exposed to dependency drift.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
slevomat/coding-standard Version ~8.22.0 | — | — |
php-parallel-lint/php-parallel-lint Version ^1.3 | — | — |
php-parallel-lint/php-console-highlighter Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.