A tool to automatically fix PHP code style
92%
Total Score
healthy
Healthy: frequent releases and active, broad project maintenance outweigh minor workflow and install-script hygiene concerns.
The package runs a post-autoload-dump install-time script, which adds execution during installation and is a minor supply-chain hygiene concern.
All 14 workflows were analyzed successfully with no untrusted checkouts or script injection. However, all 28 action references are unpinned, and one high-confidence low-severity finding reports an ad hoc package installation; broad write permissions appear in four workflows without an untrusted sink.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
react/socket Version ^1.16 | — | — |
react/stream Version ^1.4 | — | — |
sebastian/diff Version ^4.0.6 || ^5.1.1 || ^6.0.2 || ^7.0 || ^8.0 || ^9.0 | — | — |
symfony/finder Version ^5.4.45 || ^6.4.24 || ^7.0 || ^8.0 | — | — |
composer/semver Version ^3.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.