Clear documentation, tests, release notes, and a security policy make integration easier. MIT licensing, no install scripts, and active build tooling are reassuring, though the project has little usage history.
66%
Total Score
83
100
83
83
The package is only 45 days old and has 16 releases, with a median interval of about 1.7 hours. This shows active initial development but provides little long-term maintenance history.
All 20 recent commits came from one contributor, creating a meaningful continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown.
The repository has one star and no forks or watchers, so there is little external adoption evidence. Popularity is supporting evidence, making this a modest concern rather than a decisive risk.
Version v0.11.0 is not a stable major release, so the public API may still change despite the absence of prerelease versions.
The sole workflow was fully analyzed with no audit findings or untrusted checkouts, but all three action references are unpinned. That is a supply-chain hygiene gap without evidence of an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.