Clear documentation, licensing, tests, and a security policy improve confidence. The project is only 54 days old, has one active contributor, and uses five unpinned actions; pin a later release after its maintenance record grows.
68%
Total Score
88
100
89
88
This is a young package, released once 54 days ago, so its long-term maintenance record is not yet established.
All four recent commits came from one contributor, leaving maintenance dependent on a single active developer; organization backing provides some handoff capacity but does not remove the concentration risk.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
Both workflows were fully analyzed with no dangerous sinks or audit findings, and one workflow uses read-only permissions; however, all five action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
league/commonmark Version ^2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.