The MIT license, included tests, clear documentation, and low runtime dependency burden make integration straightforward. The repository has no security policy, and its workflow actions are not pinned, which weakens transparency and build hygiene.
76%
Total Score
75
100
93
50
No commits or active maintainers were recorded in the last 3 months, which is a maintenance concern. However, the recent release history shows that this does not yet indicate abandonment.
Composer build tooling is present, but no security-scanning tool was detected. This is a minor hygiene gap rather than a strong supply-chain concern for this small package.
The repository has no published security policy. For a package that processes user-entered phone data, this is a transparency gap, although it is not evidence of a security defect.
The only workflow was fully analyzed with no reported audit findings or unsafe triggers, but both action references are unpinned. Unpinned actions leave the build exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.