Package Health

spatie/shiki-php

Highlight code using Shiki in PHP

Latest 2.4.0PackagistPackagist

72%

Total Score

caution

Usable with caveats: no commits in the last three months and high-confidence unpinned workflow images.

Health Score Breakdown

Repo commit activitycaution

The repository recorded zero commits and zero active maintainers during the last three months. Although a release was published recently, this quiet activity lowers confidence in near-term maintenance.

Repo toolingcaution

Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance-process gap rather than evidence of an unsafe release.

Security policycaution

The repository has no security policy. That leaves vulnerability-reporting expectations unclear, although it does not by itself indicate abandonment.

Workflow auditcaution

All eight analyzed action references are unpinned, and the auditor found a high-confidence, high-severity unpinned container image in php-cs-fixer.yml. The workflows were fully analyzed and had no untrusted checkouts or script-injection findings, which limits the concern to workflow supply-chain hygiene.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Rias Van der Veken
Freek Van der Herten

Direct Dependencies

DependencyLast ReleaseScore
symfony/process
Version ^5.4|^6.4|^7.1|^8.0
—
—

Weekly Downloads

Info

Last Published
5 months ago
Created
5 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform