Clear documentation and a small dependency surface make adoption easier. The main limitations are that one person made all 43 recent commits, no security scanning is reported, and the workflow uses one unpinned action.
76%
Total Score
67
94
83
The repository is owned by an individual rather than an organization, so there is no provided organizational backing to offset the concentrated maintainer base.
One contributor made 100% of the 43 commits in the last three months. Because the repository is user-owned rather than organization-owned, this concentration is a genuine continuity risk.
Composer build tooling is present, but no security-scanning tool is reported. That is a modest transparency and maintenance gap, not evidence of unsafe behavior by itself.
The repository has no security policy. For a Composer plugin that affects dependency resolution, this reduces the clarity of vulnerability reporting and response expectations.
The workflow is fully analyzed, uses read-only permissions, and has no reported high- or medium-severity findings. Its single action reference is unpinned, leaving a minor reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.