The project has a clear README, tests, changelog, MIT license, and documented release notes. Its workflows avoid dangerous patterns, though the repository lacks a security policy and automated security scanning.
88%
Total Score
88
50
94
80
The package has 23 runtime dependencies, reflecting a meaningful dependency surface for its crawler and CLI functionality but not an excessive profile on its own.
There are 14 open issues and one open pull request, while no issues or pull requests were opened or closed in the last month; this is a modest maintenance-process concern but is outweighed by recent commits and releases.
The project uses Make, Composer, and Box for builds, but no security-scanning tools were detected, leaving a security-process gap.
No repository security policy was found, reducing transparency about vulnerability reporting and response.
Both workflows lack top-level token-permission declarations. No top-level write permissions were found, but explicit least-privilege settings would provide stronger assurance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
nyholm/psr7 Version ^1.6 | — | — |
symfony/mime Version ^8.1 | — | — |
symfony/yaml Version ^8.1 | — | — |
sentry/sentry Version ^4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.