The package is small and focused, with a stable major release, clear licensing, release notes, and organization backing. Maintenance has slowed, and all seven workflow actions are unpinned, leaving modest upkeep and build-integrity concerns.
70%
Total Score
75
100
88
75
The package has been published since 2019 with 19 releases, but only one release in the last 12 months; this indicates slower maintenance for a mature, focused extension.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance warning despite the recent release.
Composer build tooling is present, but no security scanning tools were detected; this is a modest transparency and hygiene gap rather than a standalone adoption blocker.
The repository has no security policy, reducing documented vulnerability-reporting transparency.
Both workflows were analyzed without audit failures or untrusted triggers, and one scopes permissions read-only. However, all seven action references are unpinned, so their moving targets weaken build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.