The repository includes tests, a changelog, and a matching README, while licensing and dependencies are straightforward. Missing security scanning and unpinned workflow actions weaken transparency and build hygiene.
58%
Total Score
75
100
83
50
The package has 14 releases since August 2017, but none in the last three years and the latest release was in May 2023, indicating stalled maintenance.
The repository had no commits and no active maintainers in the last three months, consistent with the long release gap and increasing abandonment risk.
Composer is used for the build, but no security scanning tool is configured, leaving an avoidable gap in repository-level dependency oversight.
The repository has no security policy, which makes vulnerability reporting and disclosure expectations less transparent for dependents.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three referenced actions are unpinned, weakening build reproducibility and action integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.