Recent releases and a tested, licensed package provide a solid baseline. Organization backing helps offset the concentrated contributor activity, though workflow pinning and security-policy gaps remain.
80%
Total Score
83
100
94
83
All two recent commits came from one contributor, creating concentration risk. Organization ownership provides some ability to hand maintenance off, so this is a caution rather than a severe risk.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users lack documented guidance for reporting vulnerabilities or understanding the project's security process.
The workflow audit completed cleanly with no untrusted checkouts, injection findings, or broad top-level writes. However, all three referenced actions are unpinned, weakening build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
peterpostmann/parse_uri Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.