The package is licensed, has repository tests, and includes release notes for this version. Its matching repository has a security policy and no install scripts or deprecation; organization backing softens the single-contributor concern.
76%
Total Score
67
100
88
100
The package has existed since 2019 with 22 releases, but only one release in the last 12 months indicates a slower recent cadence despite the new current release.
All recent commits come from one contributor, creating concentration risk; organization ownership provides some maintenance handoff capacity but does not remove the current single-contributor signal.
Only one commit was recorded in the last three months from one active maintainer, showing limited recent development activity.
Composer build tooling is present, but no security-scanning tooling was detected, leaving security hygiene less independently supported.
The sole workflow was fully analyzed with no injection or high-severity findings, and it does not use broad top-level write permissions. However, all four referenced actions are unpinned, leaving avoidable update and tampering risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.