The package has clear documentation, tests, a matching repository, and organizational ownership. Its maintenance record is too new to establish durability, while unpinned workflow actions and no security policy add avoidable risk.
62%
Total Score
88
100
88
67
This release is from a package created today, with only two releases and a median interval of about 1 minute; that is too little history to demonstrate dependable maintenance.
Only one commit was recorded in the last three months, and all activity is concentrated in one contributor; the package is too new for this to prove sustained maintenance.
Composer build tooling is present, but no security scanning tool was detected, leaving security checks less visible than they could be.
The repository has no security policy, so users are not given a documented vulnerability-reporting process.
The workflow audit completed cleanly with no untrusted checkout or script-injection findings, but both referenced actions are unpinned; the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.