The package includes tests, release notes, a clear README, and a low-risk dependency profile. Workflow permissions are read-only, but the single-maintainer project has no recent commits and its actions are all unpinned.
68%
Total Score
67
100
94
83
The repository recorded zero commits and zero active maintainers in the last three months, which is a concrete sign of slowed maintenance for a package with ongoing open work.
There are three open issues and four open pull requests, but none were opened or merged in the last month, indicating unresolved work and limited current activity.
Composer build tooling is present, but no security scanning tools are configured. This is a modest transparency and maintenance gap rather than evidence that the release is unsafe.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities.
Both workflows use read-only permissions and the audit found no dangerous sinks or findings. However, all four analyzed action references are unpinned, leaving build inputs less reproducible and more exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.