Clear licensing, tests, and a matching organization-backed repository support adoption. Sparse releases, no security policy, and no recent repository activity limit confidence in ongoing maintenance.
64%
Total Score
75
100
88
75
The package is about 639 days old with only three releases and a median interval of about 197 days; two releases in the last 12 months show activity, but the cadence is slow.
There were zero commits and zero active maintainers in the last three months. The repository is not archived, but this recent inactivity lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which gives maintainers and users no documented channel or process for handling vulnerabilities.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all four action references are unpinned, making workflow dependencies less reproducible.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.