The repository includes tests, a clear README, a license, and organization backing, which support basic maturity and maintainability. Missing security scanning and two unpinned workflow actions leave meaningful hygiene gaps.
60%
Total Score
75
100
89
75
This is the package's first release, published today, so there is no release track record yet; the repository and documentation provide some compensating evidence but cannot establish long-term maintenance.
There have been no commits and no active maintainers in the last three months. Because the package is only hours old, this is more consistent with limited history than confirmed abandonment, but it still leaves maintenance unproven.
Composer is used for builds, but no security-scanning tool was detected. The clean workflow audit partly compensates, while the missing scanning remains a modest transparency gap.
The repository has no security policy, leaving no documented reporting process for vulnerabilities in a package intended to handle API interactions.
The single workflow completed fully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, so their versions can change outside the repository's control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.