Healthy and reasonable to adopt, with limited history because this is a first release. It has active organizational backing, tests, clear licensing, and recent repository work, but lacks a security policy and has incomplete workflow permission declarations.
78%
Total Score
100
100
88
80
This is a first release published less than a day ago, so there is no historical release cadence or evidence of long-term stability. The active repository provides some compensation, but maturity remains unproven.
Composer build tooling is present, supporting the package workflow, but no security scanning tools were detected. The missing scanning is a modest process gap rather than evidence of abandonment.
The repository has no security policy. For a package that handles identifiers, signatures, public keys, and cloud endpoints, this is a genuine transparency and vulnerability-reporting gap.
Two workflows omit top-level token permissions and the publish workflow declares write permissions. The absence of dangerous workflow patterns is reassuring, but least-privilege configuration is not consistently explicit.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.