Documentation, tests, and release notes are in place, with an organization-backed repository updated within minutes. The project is only three days old, and all five workflow actions are unpinned; the low-confidence cache warning is a minor hygiene concern.
78%
Total Score
100
100
88
75
The package is only three days old with four releases and a median release interval of zero days. That shows active initial work but provides little evidence of long-term maintenance stability.
Composer build tooling is present. No security scanning tools were detected, which is a modest transparency and hygiene gap for a maintained package.
The repository has no security policy. This does not show abandonment, but it leaves vulnerability-reporting expectations undocumented.
The single workflow was fully analyzed and uses read-only permissions, with no untrusted checkout or script-injection paths. However, all five action references are unpinned, and a low-confidence cache-poisoning warning remains a minor hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.