The source includes tests and a clear MIT licence, but all eight GitHub Actions references are unpinned and no security scanning is configured. The package is small and has limited adoption evidence.
52%
Total Score
50
79
Only two releases were published, both on the same day, and there have been no releases in the last 12 months despite the package being over a year old. This weakens confidence in ongoing maintenance.
There were no commits and no active maintainers in the last three months. Combined with the sparse release history, this raises abandonment risk.
Composer build tooling is present, but no security scanning tools were detected. This is a hygiene gap rather than evidence that the package is unsafe to depend on.
Version 0.0.2 is not a stable major release, so the public API may still change. It is not marked as a prerelease, which partly offsets the concern.
Both workflows were fully analyzed with no dangerous triggers or audit findings, but all eight action references are unpinned. That leaves avoidable build-reproducibility and action-update risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
paragonie/halite Version ^5.1 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.