The package has a clear README, repository tests, a license, and Composer security auditing. Its workflow uses two unpinned actions and no security policy is published.
65%
Total Score
50
93
50
The package is only 39 days old and has one release, so there is little evidence of release continuity or long-term maintenance.
All recent repository commits came from one contributor, creating a high dependency on that maintainer for ongoing fixes.
Only one commit and one active maintainer were observed in the last three months, providing limited evidence of sustained maintenance.
The repository has no published security policy, which weakens the project's disclosure and response transparency for a network-facing remoting library.
The workflow was fully analyzed and uses read-only permissions with no detected audit findings, but both referenced actions are unpinned, leaving avoidable build reproducibility risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.