Tests, release notes, and MIT licensing make the package transparent to adopt. Its minimal dependency footprint is favorable, though security-process coverage is limited.
78%
Total Score
75
100
86
75
The project has existed since November 2017 and released once in the last 12 months, with a median interval of about 299 days. That is a slow cadence but not evidence of abandonment because the latest release is recent.
All two recent commits came from one contributor, leaving no demonstrated backup maintainer if that person becomes unavailable.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest gap in routine security hygiene.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
The single workflow was fully analyzed and has no dangerous triggers or audit findings, but all five action references are unpinned. The absence of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.