The package is small and easy to integrate, with no runtime dependencies and clear tests and documentation. Its sole release and lack of repository activity leave maintenance capacity unproven, while unpinned workflow actions and no security scanning add modest hygiene concerns.
63%
Total Score
75
100
86
67
This is the only release, published about 2 years and 5 months ago, with no releases in the last 12 months. The stable release and complete project structure partly offset the limited maintenance history, but the absence of follow-up releases is a real maintenance concern.
The repository recorded 0 commits and 0 active maintainers in the last 3 months, consistent with a project that may be dormant. Its single-release history provides no compensating evidence of ongoing maintenance.
The project uses Composer and Make, showing basic build tooling, but no security-scanning tool was detected. For a small stable library this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. This reduces transparency for reporting vulnerabilities, though the package's tests and documented release process provide some compensating project hygiene.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 4 action references are unpinned, leaving a modest workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.