The project has a strong release record and useful tests, documentation, and release notes. Recent repository activity is quiet, and the workflow uses unpinned actions while no security policy is published.
72%
Total Score
83
100
100
75
There were no commits and no active maintainers in the three months before collection. The recent release and push provide some compensation, but this still weakens evidence of continuing development.
The repository has no published security policy. This is a transparency gap, though it is partly offset by the repository's security scanning tooling.
The single workflow was fully analyzed with no dangerous audit findings, but both of its two action references are unpinned. That leaves a supply-chain hygiene gap despite the otherwise clean audit.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
berlioz/helpers Version ^1.5 | — | — |
league/flysystem Version ^2.0 || ^3.0 | — | — |
berlioz/http-message Version ^2.0 || ^3.0 | — | — |
berlioz/html-selector Version ^2.0 || ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.