The project has tests, a useful README, matching source files, and Composer security scanning. Its single release and zero commits in the last three months limit confidence in ongoing maintenance, while all six workflow actions are unpinned.
63%
Total Score
75
88
75
This is a young package with one release, published about 100 days ago, so there is little release history to establish sustained maintenance.
There were zero commits and zero active maintainers in the last three months, despite the package being only about 100 days old; this is a meaningful maintenance concern.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities in a tool that processes secrets.
Version v0.1.0 is not a stable major release, indicating an early API and potentially more change risk for dependents.
All three workflows were analyzed with no detected dangerous sinks or audit findings, but all six action references are unpinned, leaving avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nette/neon Version ^3.4 | — | — |
latte/latte Version ^3.0 | — | — |
tracy/tracy Version ^2.10 | — | — |
nette/bootstrap Version ^3.2 | — | — |
symfony/console Version ^6.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.