The package is small and clearly documented, with a matching repository, tests, release notes, and a recent stable release. Zero commits and no active issue or pull-request work in three months leave maintenance capacity uncertain; pin v1.0.0 for now.
68%
Total Score
50
100
100
75
The repository recorded 0 commits and 0 active maintainers in the last three months. Although the release history is recent, this lack of current development activity lowers confidence in ongoing maintenance.
There was no new or closed issue or pull-request activity in the last month, while 1 issue and 1 pull request remain open. This is a modest sign of limited current project attention.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, though it is less significant for this small Composer version-check plugin than for a security-sensitive library.
All 6 workflows were analyzed with no audit findings, no untrusted checkouts, no script injection, and all 13 action references pinned. Three workflows grant top-level write permissions, which is a mild hygiene concern, but no untrusted path reaches those permissions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.