The package has a clear README, repository tests, an MIT license, and a security policy. Its single maintainer and unpinned workflow actions leave less margin for long-term maintenance and build reproducibility.
68%
Total Score
75
100
79
100
This is the package's first release, published less than one day ago, so there is no release track record yet. The repository was updated immediately before publication, which supports active launch work but does not establish long-term maintenance.
There were no commits or active maintainers recorded in the preceding three months, but the repository is brand new and was pushed immediately before the first release; this is limited evidence rather than a confirmed collapse in maintenance.
Composer build tooling is present, but no security-scanning tool was detected. The separate repository security policy provides some compensating transparency, so this is a minor hygiene concern rather than a major health risk.
Version v0.7.0 is not a stable major release, although it is not marked as a prerelease. Consumers should expect some API evolution while the package establishes itself.
The sole workflow was fully analyzed, uses read-only permissions, and has no audited dangerous findings. All three action references are unpinned, however, leaving workflow dependencies exposed to moving revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
alto/language Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.