The package includes a substantial README, repository tests, a changelog, and a matching Apache-2.0 license. It has no install-time scripts and only three runtime dependencies.
67%
Total Score
63
100
94
83
Both workflows scope permissions at job level, but all 12 action references are unpinned and the release workflow has two high-confidence template-injection findings. The release automation therefore warrants remediation before relying heavily on its published artifacts.
Only one registry account has publishing access. The repository is user-owned rather than organization-owned, so there is no organizational backing shown to offset that concentration.
The registry namespace and repository are owned by the same individual, which supports repository identity but does not provide organizational redundancy.
All 11 recent commits came from one contributor, leaving maintenance and release knowledge concentrated in a single person.
The repository has no published security policy, leaving vulnerability-reporting expectations and response guidance unclear.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ~3.4 || ~4.1 || ~5.0 || ~6.0 | — | — |
voku/simple-php-code-parser Version ~0.21.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.