JakubMisek
Composer is a flat single layer dependency manager, so all the required files are in the first vendor. As such, there is no need to scan the 2nd vendor.
But I would suggest this to be made as a generic configuration rather than 1 specific to composer, perhaps exclude scanning vendor/**/vendor?