The repository has recent activity, two active contributors, tests, release notes, a security policy, and build scanning. Its early 0.x maturity and workflow credential findings warrant attention before production use.
78%
Total Score
75
100
88
100
The package and repository are owned by the same individual account, so the source match is clear, but there is no organization backing shown to provide maintenance redundancy.
The package is young at 114 days with four releases, including four in the last 12 months; this shows active early development but limited long-term history.
Two contributors were active recently, and the leading contributor made two of three commits; the small contributor base still creates some concentration risk.
Version v0.1.2 is a non-major release rather than a stable major version, so API and behavior changes remain more likely despite having no prerelease versions.
All six workflows were analyzed and all action references are pinned, but high-confidence findings report template injection, blanket GitHub App permissions, and inherited secrets; these are workflow hygiene and credential-scope concerns, not evidence of an unsafe release trigger.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/container Version ^2.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
psr/http-message Version ^2.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.