Clear licensing, a substantial README, and repository tests support straightforward adoption. The repository had no commits in the last three months, while all 11 workflow actions are unpinned; recent releases partly offset those maintenance and build-hygiene concerns.
78%
Total Score
50
93
75
There were zero commits and zero active maintainers in the last three months. The recent release history provides some compensation, but the current development pause remains a maintenance concern.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and assurance gap.
The repository has no security policy, which makes vulnerability-reporting expectations less clear for dependents.
All four workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 11 action references are unpinned, a build-integrity hygiene weakness without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/finder Version ^6.4|^7.4|^8.0 | — | — |
entropy/entropy Version ^0.4.2 | — | — |
nikic/php-parser Version ^5.7 | — | — |
webmozart/assert Version ^2.0 | — | — |
ondram/ci-detector Version ^4.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.