This release appears healthy and suitable for dependency use: it has a stable major version, 102 releases over roughly 2 years, 80 releases in the last 12 months, and very recent repository activity. The linked organization-owned repository is active, has 24 contributors in the last 3 months, substantial issue and pull-request throughput, tests, documentation, changelog coverage, and clear package references. The main deductions are supply-chain hygiene concerns in the repository: no security policy, limited explicit workflow permission declarations, two workflows with top-level write permissions, and one detected script-injection pattern. These merit review but do not outweigh the strong maintenance and transparency evidence.
88%
Total Score
100
50
94
70
All 15 workflows were analyzed with no pull_request_target or untrusted-checkout findings, but one workflow contains a script-injection pattern. This is a concrete workflow-security concern requiring review.
The release declares 44 runtime dependencies, reflecting a broad framework scope and increasing transitive maintenance exposure. The dependency count is a moderate consideration, but it is not independently severe for a full-stack framework.
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning automation is a genuine hygiene gap, though it does not outweigh the repository's strong activity and build evidence.
No repository security policy was found. This reduces vulnerability-reporting transparency and is a maintenance hygiene gap, although the active repository and organization backing provide some compensation.
Thirteen of 15 workflows lack top-level permission declarations, two workflows grant top-level write permissions, and no workflows declare read-only permissions. Broad or implicit token permissions increase CI supply-chain exposure and warrant tightening.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/cache Version ^3.0 | — | — |
psr/clock Version ^1.0.0 | — | — |
filp/whoops Version ^2.15 | — | — |
symfony/uid Version ^7.1|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.