Tests, documentation, release notes, and a matching MIT license make the package straightforward to adopt. Its GitHub workflows leave all six actions unpinned, adding a modest reproducibility risk despite otherwise clean workflow auditing.
68%
Total Score
75
100
88
83
The package has three releases over about ten months, with the latest published about eight months ago. This shows an established release pattern, but the recent gap limits confidence in ongoing maintenance.
There were zero commits and zero active maintainers in the last three months. Combined with the latest release being about eight months ago, this is a meaningful sign of currently quiet maintenance.
The repository uses Composer, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
All three workflows were analyzed successfully and no dangerous audit findings, untrusted checkouts, or script injections were reported. However, all six action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.