Strong tests, release notes, and documentation support adoption. GitHub Actions uses seven unpinned references and the repository has no security policy, so maintenance hygiene is weaker.
68%
Total Score
50
88
50
The package has existed since June 2020 but has only four releases, with one release in the last 12 months. The recent v3.0.0 release is positive, but the sparse history limits confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Although v3.0.0 was recently published, the current lack of commit activity raises a maintenance concern.
Composer build tooling is present, but no security-scanning tool was detected. This is a hygiene gap rather than evidence that the package is unsafe.
The repository has no security policy. That reduces transparency about vulnerability reporting and handling, though it does not by itself show abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all seven action references are unpinned, which weakens build reproducibility, while the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.