The MIT license, clear README, release notes, and recent commits support adoption. Keep ownership continuity and workflow image pinning in mind for long-lived or security-sensitive use.
68%
Total Score
67
100
94
75
The repository is owned by an individual rather than an organization, so the single-maintainer concentration is not offset by visible organizational backing.
All 8 recent commits came from one contributor, leaving the project dependent on a single maintainer for ongoing fixes and releases.
Composer build tooling is present, but no security scanning tool was detected, leaving security-focused maintenance less visible.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
The workflow audit completed fully and found no untrusted checkouts or script injection, but both container-image findings were high severity with low confidence and both analyzed references were unpinned. This is a workflow hygiene weakness rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.