This release appears suitable to depend on from a supply-chain health perspective: it has a long release history, a stable non-prerelease version, recent releases, an active non-archived repository, organization backing, matching repository identity, tests, changelog, licensing, build tooling, and security scanning. Recent repository activity is modest but includes two commits from two contributors and two merged pull requests, which reduces bus-factor concern. The main reservations are the repository's lack of a security policy, the workflow's absence of top-level token permissions, and very low public popularity; these are meaningful transparency and governance gaps, but they are not outweighed by evidence of abandonment or severe release risk.
87%
Total Score
100
100
94
80
The repository has zero stars, forks, and watchers, indicating little visible community adoption or independent validation. Popularity is supporting evidence rather than a verdict, so this is a caution rather than a severe health failure.
No repository security policy was found, leaving vulnerability-reporting and response expectations undocumented. This is a transparency gap, although it does not by itself indicate abandonment.
The one workflow lacks top-level token permissions, so its effective GitHub Actions permissions are less explicit than recommended. No top-level write permissions were observed, limiting the severity of this governance gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twilio/sdk Version ^7 || ^8 | — | — |
ramsey/uuid Version ^3.8 || ^4.0 | — | — |
monolog/monolog Version ^1.24 || ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.