Clear documentation, tests, release notes, and a security policy improve transparency. The CI workflow leaves all four action references unpinned, and no automated security scanning is reported.
67%
Total Score
75
88
75
The package is only 2 days old with four releases and a median interval of about 17 hours, so long-term maintenance and compatibility are not yet established.
Two contributors were active, but one accounts for 85% of the 20 recent commits, leaving maintenance capacity concentrated in one person.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest transparency and maintenance gap.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings, but all four action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.