Provide information about package changes based on changelog files that are bundled with releases; provide tools for generating documentation files from changelog sources
78%
Total Score
67
100
67
post-install-cmd and post-update-cmd scripts run during Composer operations, increasing installation behavior and review considerations beyond a passive library.
All recent commits came from one contributor. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, indicating limited recent development activity despite the recent package release.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The complete workflow audit found no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, which is a supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
seld/jsonlint Version ^1.7.1 | — | — |
symfony/console Version ^4.0 || ^5.0 || ^6.0 || ^7.0 || ^8.0 | — | — |
symfony/process Version >=4.2 | — | — |
mustache/mustache Version >=v2.12.0 | — | — |
camspiers/json-pretty Version ^1.0.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.