Faker allows you to generate realistic fake data for your php applications
82%
Total Score
healthy
Healthy: active releases and a maintained, multi-contributor repository outweigh minor license and workflow hygiene concerns.
The artifact declares MIT but its license file is detected as Apache-2.0, creating a genuine licensing inconsistency despite a license file also being present in the repository.
Post-install and post-update Composer scripts add install-time behavior that consumers should understand, but this is a moderate transparency concern rather than a severe health risk on its own.
Composer is used for builds, but no security-scanning tool was detected. The missing scanner is a modest transparency gap, not evidence of poor maintenance by itself.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified and creating a minor transparency gap.
Both workflows were analyzed without failed files or dangerous sinks, and one scopes permissions at job level. However, all 5 analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
phpdocumentor/reflection-docblock Version ^5.6|^6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.