The package includes a clear README, tests, an MIT license, and release notes, with no install-time scripts or archive status. Workflow pinning and a missing security policy leave modest supply-chain and transparency gaps.
66%
Total Score
75
100
88
67
This is the package's first release, published less than a day ago, so there is no established release track record or long-term maintenance evidence yet.
All 18 recent commits came from one contributor, so maintenance depends entirely on that person and has a high handoff risk.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest project-hygiene gap.
The repository has no published security policy, which makes vulnerability reporting and response expectations less transparent.
The only workflow was fully analyzed with no dangerous sinks or audit findings, but both action references are unpinned, so their contents can change without a repository change.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
doctrine/orm Version ^3.6.7 | — | — |
doctrine/dbal Version ^4.4.3 | — | — |
google/cloud-secret-manager Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.