The repository includes tests, a changelog, a security policy, dependency scanning, and a correctly licensed package. Its install-time script and broad workflow permission need attention as the project matures.
68%
Total Score
75
86
67
A post-autoload-dump install-time script runs during Composer operations, adding execution surface for consumers even though the signal gives no evidence of harmful behavior.
Only one registry publishing account is present, limiting visible publishing redundancy; the repository is also maintained by a single user rather than an organization.
This is the first release, published today, so there is no release history or cadence demonstrating sustained maintenance yet.
Version 0.1.0 is not a stable major release, which indicates an early API and maintenance stage despite not being marked as a prerelease.
Both workflows were fully analyzed with no audit findings, all five action references pinned, and one workflow using read-only permissions. One workflow has top-level write permissions, a mild hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^7.4.19||^8.1.7 | — | — |
nikic/php-parser Version ^5.9 | — | — |
illuminate/support Version ^12.0||^13.0 | — | — |
thecodingmachine/safe Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.