Clear documentation, tests, licensing, and security scanning make the package easy to evaluate and maintain locally. Its workflow is mostly clean, though two of three action references are unpinned.
68%
Total Score
50
86
67
The repository is owned by a GitHub user rather than an organization, so there is no organizational backing to offset the concentrated maintainer base.
The package is only 1 day old, despite 11 releases, and releases arrived roughly every 1.4 hours. This shows active initial work but provides little evidence of sustained maintenance.
One contributor made 100% of the recent commits. Because the repository owner is an individual rather than an organization, this concentration creates meaningful continuity risk.
There were 3 commits in the last 3 months and activity is still current, but only one active maintainer is shown. The short history limits confidence in long-term maintenance.
The repository has no security policy. This is a transparency gap for reporting vulnerabilities, although the available composer-audit tooling provides some compensation.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4 || ^8.0 | — | — |
nikic/php-parser Version ^5.9 | — | — |
carthage-software/mago Version 1.50.* | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.