The repository includes extensive tests, a changelog, matching package references, and a clear MIT license, while Composer security scanning supports sound project practice. All 10 workflow actions are unpinned, and no security policy is present.
62%
Total Score
50
90
50
The package has only one release, published about 311 days ago, so there is little release history to demonstrate sustained maintenance.
The repository recorded zero commits and zero active maintainers in the last 3 months. This is concerning for a package whose only release is still relatively recent, although it does not establish abandonment by itself.
The repository has no security policy, which weakens vulnerability-reporting transparency for a library intended for application integration.
All four workflows were analyzed successfully and have no dangerous triggers, sinks, or audit findings. However, all 10 analyzed action references are unpinned, leaving the build exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.