The package has clear MIT licensing, repository tests, and release notes for this version. Its small contributor base and unpinned CI action references warrant routine caution.
80%
Total Score
75
100
94
75
The repository is owned by an individual user rather than an organization, so the concentrated contributor activity has no visible organizational handoff to compensate for it.
Two contributors were active, but one made 16 of 17 recent commits, leaving maintenance heavily concentrated in a single person.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or excessive permissions, but all seven action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.