Testing, a release note for 2.0.2, and a clear licence support dependable maintenance. GitHub workflows use unpinned actions and contain high-confidence template-injection findings; no security policy or scanning is visible.
70%
Total Score
100
86
50
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest assurance gap for a package with seven runtime dependencies.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
Version 2.0.2 is a stable major release and is not a prerelease, but 70% of recent releases were prereleases, which adds some release-quality uncertainty.
All five workflows were analyzed, but all 12 action references are unpinned and high-confidence template-injection findings appear in the test and release workflows. The audit found no untrusted checkout or script-injection trigger, so this is workflow hygiene risk rather than a severe standalone health failure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
beberlei/assert Version ^3 | — | — |
php-http/discovery Version ^1.20 | — | — |
civicrm/civicrm-core Version >=5.80 | — | — |
civicrm/civicrm-packages Version >=5.80 | — | — |
php-http/multipart-stream-builder Version ^1.4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.