The package has a clear license, a recent release, and a small dependency footprint. Its repository uses Composer and security scanning, but it lacks a security policy and has limited maintenance depth.
70%
Total Score
50
100
100
67
The registry package and repository are owned by the same individual user, confirming the repository is directly associated with the package. It also means the project has no indicated organizational backing to offset its concentrated maintenance.
All recent commits came from one contributor, giving the project a single-person maintenance dependency. The repository is user-owned rather than organization-backed, so there is no provided compensating handoff signal.
Only one commit was recorded in the last three months, from one active maintainer. Recent activity exists, but the low volume provides limited evidence of sustained maintenance capacity.
No repository security policy was found. This is a transparency gap for reporting vulnerabilities, though it is not by itself evidence of unsafe code.
The single workflow was fully analyzed with no detected injection or high-confidence audit findings, but both of its two action references are unpinned. The workflow also lacks a top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.