The package is easy to inspect and consume, with tests, a clear README, and only one runtime dependency. The maintainer is active, but all recent commits come from one person and all six workflow actions are unpinned.
78%
Total Score
75
100
93
50
All 54 recent commits came from one contributor, so maintenance depends entirely on a single person. The active release and commit history partly compensate, but do not remove the succession risk.
The project uses Make and Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap for a package distributed as a dependency.
The repository has no security policy. This does not show a vulnerability, but it leaves reporting and response expectations undocumented.
All three workflows were analyzed successfully with no audit findings, no untrusted checkouts, and no script injection. However, all 6 action references are unpinned, leaving their fetched code less reproducible and increasing update risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.