Its focused scope and low runtime dependency count limit integration risk. The source has tests and release notes, but CI uses two unpinned references and reports inherited secrets.
70%
Total Score
75
100
94
75
The repository recorded zero commits and zero active maintainers during the last three months. Although a recent release and May 2026 push show the project is not abandoned, the current maintenance pace warrants caution.
Composer build tooling is present, but no security-scanning tool was detected. For a small Composer plugin this is a modest transparency gap rather than a severe risk.
The repository has no published security policy. This weakens vulnerability-reporting transparency, although the package's clear ownership and established source repository provide some compensating context.
The single workflow was fully analyzed and uses read-only permissions, with no untrusted checkout or script-injection findings. However, both action references are unpinned and high-confidence secrets-inherit findings show credentials are passed more broadly than necessary, creating a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.