The package has clear documentation, tests, a matching source repository, and a modest but steady release history. Its tiny project footprint, absent security policy, and unpinned workflow actions leave less maintenance and build assurance than a mature dependency.
68%
Total Score
50
100
88
50
There were no commits and no active maintainers in the last three months, indicating that development activity has currently stalled even though releases remain recent.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and review gap.
The repository has no security policy, which makes vulnerability reporting and response expectations less clear for dependents.
Version v0.8.0 is not a prerelease, but the package remains below a stable major version, so compatibility expectations are somewhat less certain.
The single workflow was fully analyzed, uses read-only permissions, and has no audited findings, but all three action references are unpinned, weakening build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.