Usable with caveats: this is a stable, recently released package backed by an active Facebook repository with tests, documentation, and a small dependency footprint. However, no maintainers committed in the last three months, security scanning is absent, and most workflows do not declare permissions.
72%
Total Score
67
100
94
83
There were no commits and no active maintainers during the last three months. This weakens confidence in ongoing maintenance despite the recent release and repository push.
The repository has six open issues and five open pull requests, with two new issues in the last month but no closures. The open backlog is a modest maintenance concern, though it does not by itself show abandonment.
Composer is used as the build tool, but no security scanning tools were detected. The missing scanning is a transparency and maintenance gap, not evidence that the package is unsafe.
Ten of 12 workflows lack top-level permissions, one workflow declares write permissions, and only one declares read-only permissions. This is a workflow-hardening gap, although the dangerous-workflow checks found no exploit-prone patterns.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.