Its license, tests, changelog, and release notes make the codebase easy to inspect. Pinning is weak because all four workflow actions are unpinned, and registry publication has not kept pace with recent repository commits.
61%
Total Score
63
100
89
75
The repository is owned by an individual user rather than an organization, so the concentrated recent commit share has no organizational handoff evidence to offset it.
Only one registry release exists, published about 7 years and 9 months ago, with no releases in the last 12 months. Recent repository activity partly offsets this, but the distributed release is very stale.
Two contributors were active, but one made 7 of 8 recent commits, leaving maintenance substantially concentrated while still providing a second active contributor.
There are 47 open issues but no issues or pull requests were opened or closed in the last month, suggesting unresolved maintenance demand and limited issue throughput.
Composer is used for builds, but no security-scanning tooling is reported. The build tooling is positive; the missing security tooling is a minor transparency gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.