Clear MIT licensing, repository tests, release notes, and a security policy support adoption. The tiny dependency surface and active repository are reassuring, though the project remains young.
73%
Total Score
90
100
83
88
The package is young at 254 days old with two releases and a median interval of about 194 days; this is limited history, but the latest release is recent rather than abandoned.
One contributor made all five recent commits, creating a meaningful continuity risk despite organization backing.
The repository has only 2 stars and 1 fork, so external adoption evidence is limited; popularity is supporting evidence rather than a requirement for a small library.
Composer build tooling is present, but no repository security scanning tools were detected, leaving a modest security-process gap.
The workflow is fully analyzed, uses read-only permissions, and has no dangerous sinks or audit findings. However, all 3 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.