Documentation, tests, licensing, and a security policy provide a solid foundation. Maintenance currently depends on one contributor, while all six workflow action references are unpinned, so long-term resilience and build reproducibility are weaker.
68%
Total Score
83
88
83
This is a young package with one release in 44 days, so there is little release history from which to judge long-term maintenance stability.
All 31 recent commits came from one contributor, creating concentration risk; organization backing provides some ability to hand off maintenance but does not remove the current dependency on one active contributor.
Composer build tooling is present, but no security-scanning tool was detected, leaving an avoidable transparency and monitoring gap.
All three workflows were analyzed successfully and have no detected injection or high-severity findings, but all six action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.