Its MIT licensing, repository tests, and release notes make the package easy to inspect. Recent commits are absent, while both workflows grant broad write access and use unpinned actions; install-time scripts add review overhead.
67%
Total Score
50
94
50
The package runs post-install and post-update commands, creating additional execution during dependency operations and warranting review of those scripts.
The repository recorded zero commits and zero active maintainers during the last three months, which is a maintenance concern despite the recent push and pull-request activity elsewhere.
The repository uses Make and Composer build tooling, but no security scanning tools were detected, leaving a modest assurance gap.
No repository security policy was found, reducing transparency about how vulnerabilities are reported and handled.
Both workflows use top-level write permissions and all two analyzed action references are unpinned, weakening build reproducibility and widening token access. The audit found no untrusted checkout, script injection, or high-confidence dangerous workflow finding, so this remains a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.2 | — | — |
react/http Version ^1.11.0 | — | — |
react/event-loop Version ^1.5.0 | — | — |
wyrihaximus/psr-3-utilities Version ^2.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.