The package is well documented and tested, with a clear MIT license and a recent stable release. Organization backing offsets the concentrated commit activity, while unpinned workflow actions and the lack of a security policy leave modest maintenance concerns.
80%
Total Score
88
100
88
75
The package has existed for nearly two years with seven releases and a latest release in June 2026, though only one release occurred in the last 12 months, indicating slower recent cadence.
All 18 recent commits came from one contributor, creating a real continuity risk; organization ownership provides some handoff capacity but does not remove the concentration.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest gap in project hygiene.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no high-confidence audit findings or dangerous untrusted triggers. However, all three referenced actions are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.