The package includes a substantial README, tests, a matching Apache-2.0 license, and read-only workflow permissions. Its two workflow actions are unpinned, and the project has no security policy; the release is too new to establish maintenance history.
68%
Total Score
100
79
50
This is the first release, published today, so there is no release history or cadence to demonstrate reliability. Its age is too short to establish abandonment, but it limits confidence.
The repository uses Composer build tooling, but no security scanning tools were detected. For a new build-time generator, this is a modest transparency and hygiene gap.
No security policy was found in the repository, leaving vulnerability reporting expectations unspecified. This is a documentation gap rather than evidence that the package is unsafe.
The assessed version is v0.1.0-alpha.1 and all recent releases are prereleases, indicating an immature interface that may change before production stability.
The workflow is fully analyzed, has read-only permissions, and has no reported high- or medium-confidence findings. However, both of its two action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.