There have been no commits in the last three months, and all 13 GitHub Actions references are unpinned. A recent release with tests, release notes, and an active repository provides some maintenance evidence.
43%
Total Score
75
88
50
The package is reported as borrowing the identity of spatie/array-to-xml, with borrows_lookalike_identity true. Although artifact overlap is 0.0 and the names differ semantically, this is strong evidence that consumers may have wanted the established lookalike instead.
The repository recorded 0 commits and 0 active maintainers in the last three months, which weakens evidence of ongoing maintenance. The recent release and push activity provide some counterweight but do not replace current commits.
The repository has no security policy, leaving disclosure and response expectations undocumented. Dependabot and other repository tooling provide limited compensating evidence but do not replace a published policy.
The audit analyzed all 5 workflows with no failed files or findings, and the pull_request_target workflow has no untrusted checkout or script-injection sink. However, all 13 action references are unpinned, and one workflow grants top-level write access, creating a reproducibility and permissions-hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^5.3|^6.0|^7.0|^8.0 | — | — |
symfony/finder Version ^5.3|^6.0|^7.0|^8.0 | — | — |
symfony/console Version ^5.3|^6.0|^7.0|^8.0 | — | — |
permafrost-dev/code-snippets Version ^1.2.0 | — | — |
permafrost-dev/php-code-search Version ^1.10.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.