Tests, release notes, a useful README, and a matching MIT license provide solid consumer documentation. Organization backing and a recent release help, while install-time hooks, absent security scanning, and unpinned workflow actions add modest overhead.
68%
Total Score
75
100
94
67
The package defines post-install and post-update Composer scripts. These add execution during dependency operations and therefore warrant some caution even though the signal does not establish harmful behavior.
The repository recorded zero commits and zero active maintainers in the last three months. This is a meaningful recent-maintenance gap, although the package still had a release during that period.
Composer build tooling is present, but no security-scanning tool was detected. That is a transparency and maintenance weakness, not evidence that the release is unsafe.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a modest transparency gap for a maintained integration library.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all six action references are unpinned, reducing build reproducibility and increasing exposure to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
webmozart/assert Version ^1.11|^2.0 | — | — |
symfony/http-kernel Version ^7.0.3|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.