The package is well documented and tested, with a small runtime dependency set. The license files conflict, workflow actions are unpinned, and the repository has no security scanning. Pin this version only if those maintenance and licensing concerns are acceptable.
58%
Total Score
50
100
81
75
The manifest declares MIT and a license file is present, but the artifact license file was detected as GPL-3.0. This unresolved mismatch creates a meaningful adoption and compliance concern.
The package has had no releases in the last 12 months; its latest release was published on January 2, 2025, despite being about 20 months old at collection time. This indicates stalled maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, supporting the concern that development has stopped rather than merely slowed.
Composer build tooling is present, but no security-scanning tool was detected in the repository. That weakens supply-chain hygiene, though it is not evidence that the package is unsafe.
All 12 analyzed GitHub Actions references are unpinned, which leaves builds exposed to changing action revisions. The audit found no untrusted checkouts, script injection, dangerous triggers, or high-severity findings, and most workflows omit top-level permissions without granting top-level write access.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.