The source is well tested and the package has a long, steady release history. Maintenance is concentrated in one contributor, and workflow actions are all unpinned; the missing security policy adds a smaller transparency gap.
78%
Total Score
67
100
94
75
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not visibly compensated by organizational backing.
All 3 commits in the last 3 months came from one contributor, so maintenance continuity depends heavily on a single person.
Composer build tooling is present, but no security-scanning tooling was detected. The lack of scanning modestly reduces visible supply-chain hygiene.
The repository has no security policy, leaving reporting and response expectations undocumented. This is a transparency gap, not evidence that the package is unsafe.
Both workflows were fully analyzed with no untrusted checkouts, script injection, or audit findings, and neither grants top-level write permissions. However, all 8 action references are unpinned, leaving versions exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.