The package is small, tested, licensed, and free of install-time scripts. Its workflow uses seven unpinned actions, while no security policy or automated scanning is present.
65%
Total Score
67
100
86
67
One registry maintainer is consistent with the small project, but it provides little publishing redundancy when combined with the repository's single active contributor.
All three recent commits came from one contributor, leaving maintenance highly concentrated and increasing abandonment risk if that person becomes unavailable.
The repository name does not match the package name and its README does not mention this package, so the linkage is not clearly established even though the artifact and repository trees match.
Composer is used for builds, but no security-scanning tooling is present; this is a modest transparency and monitoring gap for a dependency project.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.