The package is licensed and includes tests, while its workflow uses read-only permissions. The missing security policy and unpinned workflow action are modest transparency and reproducibility gaps.
88%
Total Score
100
94
75
Composer is used as the build tool, but no security-scanning tools were detected. The missing scanner is a modest supply-chain transparency gap, not proof of unsafe code.
The repository has no security policy. This weakens vulnerability-reporting transparency, although active commits and organization ownership provide some compensating maintenance capacity.
The single workflow was fully analyzed, has read-only permissions, and produced no audit findings. However, its one action reference is unpinned, leaving a modest reproducibility and action-integrity gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.