The project includes tests, release notes, and security scanning, with no install-time scripts. Its pre-1.0 status and missing security policy warrant normal dependency review.
78%
Total Score
75
94
67
Two contributors were active, but one made 38 of 44 commits, or about 86%. The second contributor provides some continuity, but maintenance remains concentrated.
The repository has no security policy. This is a transparency and response-process gap, although the reported security-scanning tools provide partial compensation.
Version 0.1.14 is not yet at a stable major version, so compatibility may change more readily than in a mature 1.x package. It is not marked as a prerelease, which partly offsets that concern.
All three workflows were analyzed with no untrusted checkouts, script injections, or audit findings. However, all seven action references are unpinned and two workflows grant top-level write permissions, creating moderate workflow hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/console Version ^7.4 | — | — |
helgesverre/toon Version ^3.2 | — | — |
nikic/php-parser Version ^5.8 | — | — |
voku/simple-php-code-parser Version ^0.22.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.