The package is clearly licensed, documented, dependency-light, and backed by an organization with repository tests. Its limited release history and concentrated development leave less evidence of long-term resilience.
68%
Total Score
83
100
88
75
This is a 48-day-old package with only one release, so there is little observed evidence of sustained release maintenance or compatibility handling.
All 19 commits in the last three months came from one contributor, leaving a concentrated maintenance path. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tools were detected, leaving a modest gap in repository security hygiene.
The repository has no security policy, reducing transparency about vulnerability reporting and response expectations.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or write-wide permissions. However, all four action references are unpinned, so their revisions can change unexpectedly.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.