The package is licensed, documented, tested, and backed by a repository with release notes. Its security policy and automated security scanning are absent, while all four workflow actions are unpinned; the project is also too new to demonstrate sustained maintenance.
68%
Total Score
81
75
All six releases were published within about two hours, and the package is only 0 days old. This shows active initial work but provides no evidence of sustained maintenance yet.
Composer is used as a build tool, but no security scanning tools are configured. That leaves a modest transparency and maintenance gap.
The repository has no security policy. For a plugin handling backend integrations, this makes vulnerability reporting and response expectations unclear.
Version v0.1.6 is a non-stable 0.x release, so compatibility and maintenance maturity are not yet established. It is not marked as a prerelease, which partly reduces the concern.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
october/rain Version >=4.2 | — | — |
composer/installers Version ^1.0 || ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.