The repository includes tests, release notes, a security policy, and a matching source tree. Its same-day history, 0.x version, and unpinned workflow actions leave maturity and build integrity less established.
72%
Total Score
83
100
81
83
The repository is owned by an individual account rather than an organization, so the single registry maintainer does not benefit from visible organizational handoff capacity.
This is a very new package: all three releases appeared on the same day, so there is not yet enough history to establish long-term maintenance.
Composer build tooling is present, but no security-scanning tooling was detected, leaving automated security coverage less established.
v0.2.0 is a non-prerelease 0.x version, but the pre-1.0 major indicates that compatibility and API stability are not yet mature.
All three workflows were analyzed without high-confidence audit findings or untrusted checkouts, but all six action references are unpinned and two workflows grant top-level write permissions. This is a meaningful build-integrity and token-scope hygiene concern, though not severe on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.