The release has regular updates, tests, release notes, and two active contributors. Its small audience and lack of repository security policy or automated security scanning leave some maintenance and transparency gaps.
78%
Total Score
100
100
89
67
The repository has only 3 stars, 0 forks, and 1 watcher, indicating limited adoption evidence. This is supporting caution rather than a maintenance verdict because recent activity is present.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest security-process gap.
The repository has no security policy, so vulnerability reporting and disclosure expectations are not documented.
Both workflows were analyzed successfully with no reported audit findings or untrusted checkout or script-injection paths. However, all 8 action references are unpinned, and one workflow grants top-level write permissions, creating workflow hygiene and token-scope concerns.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0|^2.0|^3.0 | — | — |
psr/simple-cache Version ^1.0|^2.0|^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.