The project has clear documentation, release notes, repository tests, and security tooling. Recent work is limited to one contributor, while every workflow action is unpinned and the docs workflow has high-confidence template-injection findings.
68%
Total Score
75
100
100
75
A post-update-cmd lifecycle script runs during Composer updates, adding install-time behavior that deserves caution even though no more severe behavior is shown.
One contributor made all commits in the last three months. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
Only one commit was recorded in the last three months, which indicates limited recent maintenance despite the recent release.
All 11 action references are unpinned, and the docs workflow has four high-confidence template-injection findings plus top-level write permissions. No untrusted checkout or script-injection trigger was found, so this is a serious hygiene concern rather than an automatic severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.