The package includes a README, changelog, release notes, tests in the repository, and a security policy. Its only notable concerns are that all six recent commits came from one contributor and all three workflow actions are unpinned.
78%
Total Score
83
100
81
100
The package is young at 43 days with two releases spaced about 43 days apart, so its maintenance record is still limited rather than established.
One contributor made all six commits in the last three months, leaving maintenance dependent on a single active contributor.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest tooling gap.
v0.8.0 is not a stable major release, but it is not marked as a prerelease and recent releases show no prerelease churn.
The workflow audit analyzed all one workflow with no failed files, read-only permissions, and no dangerous findings. However, all three action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atelier/svg Version ^1.0 | — | — |
atelier/layout Version ^0.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.