Healthy and suitable to depend on. It has a long release history, a recent stable release, active commits, and organization backing; the main caveats are limited contributor depth and missing repository security-policy and workflow permission declarations.
84%
Total Score
75
94
75
Two contributors are active, but one made about 73% of the recent commits, leaving some maintainer concentration risk; organization backing provides partial resilience.
There are 8 open issues and no recent issue or pull-request activity, which is a modest transparency and responsiveness concern, although recent commits and releases provide stronger evidence of ongoing work.
Composer is used for builds, but no security-scanning tooling is detected, leaving a gap in the project's automated security hygiene.
The repository has no security policy, so its process for receiving and communicating vulnerability reports is unclear.
All 3 workflows omit top-level token permissions declarations, reducing explicit least-privilege guarantees even though none declares top-level write access.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.