The package includes a substantial README, repository tests, a changelog, a clear MIT license, and active recent development. Its small maintainer base and unpinned CI action references leave less resilience and reproducibility than a mature dependency should have.
72%
Total Score
67
100
100
67
The repository is owned by an individual account rather than an organization, so the single-contributor concentration is not visibly offset by broader project backing.
All 30 recent commits came from one contributor, so maintenance depends entirely on a single person and has limited handoff resilience.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a security-focused package.
The sole workflow was fully analyzed with no audit findings or untrusted checkouts, but all four action references are unpinned, reducing build reproducibility and increasing dependency drift risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/simple-cache Version ^2.0 || ^3.0 | — | — |
guzzlehttp/guzzle Version ^7.8 | — | — |
illuminate/collections Version ^11.0 || ^12.0 || ^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.