Documentation, tests, and release notes make the upgrade path clear. MIT licensing, modest dependencies, and an organization-backed project are reassuring; unpinned workflow actions and no security policy warrant routine review.
84%
Total Score
100
100
94
67
Composer build tooling is present, but no repository security-scanning tool was detected, leaving a modest assurance gap.
The repository has no SECURITY policy, which reduces transparency about vulnerability reporting and response procedures.
Both workflows were analyzed without reported audit findings or untrusted checkouts, and one scopes permissions at job level. However, all 5 action references are unpinned, leaving avoidable build-reproducibility and action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/http-message Version ^1.0 || ^2.0 | — | — |
aura/filter-interface Version ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.