The repository is actively maintained, licensed, tested, and backed by an organization. Its GitHub Actions include a high-confidence unpinned container image finding, adding avoidable supply-chain exposure.
45%
Total Score
100
100
89
75
This package borrows the identity of spatie/ignition, which has far more downloads and stable releases; the indicator explicitly marks borrows_lookalike_identity as true. That is strong evidence consumers may have intended the established package instead.
No repository security policy was found, which slightly reduces disclosure transparency. This is a hygiene gap rather than evidence of abandonment or unsafe code.
All 8 action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in php-cs-fixer.yml. The pull_request_target workflow has no untrusted checkout or script-injection sink, which limits the broader workflow risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/config Version ^5.4|^6.4|^7.4|^8.0 | — | — |
spatie/ignition Version ^1.0 | — | — |
symfony/http-kernel Version ^5.4|^6.4|^7.4|^8.0 | — | — |
symfony/http-foundation Version ^5.4|^6.4|^7.4|^8.0 | — | — |
symfony/event-dispatcher Version ^5.4|^6.4|^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.