The repository has two active contributors, matching package and project names, and useful release documentation. GitHub Actions references are unpinned and the repository has no security policy, leaving avoidable maintenance and supply-chain hygiene gaps.
72%
Total Score
100
100
83
75
This is the first and only release, published less than a day ago, so there is no track record for sustained maintenance or release reliability.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no published security policy, which makes vulnerability reporting and coordinated disclosure less transparent.
v0.1.0 is an early major version, which indicates an immature API and a higher chance of breaking changes despite not being marked prerelease.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, so build inputs are less reproducible and receive a hygiene caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.