The repository has clear documentation, active recent work, and organizational backing. Pin a specific version and expect a fast-moving early-development API.
67%
Total Score
100
100
79
50
The package is only 56 days old with two releases, both arriving within about 15 hours. That is limited evidence of long-term maintenance, although the repository shows recent development.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest repository hygiene gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations and response procedures unclear.
Version 0.1.1 is an early, non-stable-major release, so APIs and behavior may still change substantially. The explicit release notes and active repository partly compensate for the maturity gap.
All 9 analyzed action references are unpinned, and one workflow grants top-level write permissions. The workflow_run trigger has no untrusted checkout or script-injection sink, so these remain hygiene concerns rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.