The MIT license, focused package tree, and security scanning make adoption clearer. Install hooks and the missing security policy warrant routine operational review.
78%
Total Score
75
100
100
50
The package runs post-install and post-update Composer scripts. These add installation-time execution exposure, although the signal does not show harmful behavior.
The repository is owned by an individual rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
One contributor made 100% of the 63 commits in the last three months. This concentrates maintenance risk even though recent activity is high.
The repository has no published security policy. That weakens transparency around vulnerability reporting, though active development and Psalm scanning partly compensate.
Both workflows were analyzed successfully with no untrusted checkout, injection, or audit findings. However, all 23 action references are unpinned and one workflow grants top-level write access, creating workflow supply-chain and permission hygiene concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabas/edifact Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.