A clear license, lean runtime dependency set, and documented release notes improve transparency. The workflow leaves all six actions unpinned and the project has no security policy, while maintenance is concentrated in two contributors.
82%
Total Score
83
100
86
75
The package is only 54 days old, so its long-term maintenance record is limited, but it has 11 releases in that period and a recent latest release.
Two contributors are active, but the leading contributor made 13 of 17 commits, or about 76%, leaving maintenance somewhat concentrated.
Composer build tooling is present, but no security-scanning tool is configured. That is a modest transparency and maintenance gap, not evidence of an unsafe release by itself.
The repository has no security policy, so users have no documented vulnerability-reporting process or disclosure guidance.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.