Documentation, tests, licensing, and a security policy provide a solid foundation. The release workflow uses broad write permissions and all nine action references are unpinned, increasing maintenance and build-integrity concerns.
68%
Total Score
50
100
81
100
The registry and repository are owned by the same individual account, which supports attribution but provides no organization-level maintenance redundancy.
This is the project's only release, published 44 days ago, so there is little release history from which to judge long-term maintenance.
All recent commits come from one contributor, leaving maintenance dependent on a single person. The repository is user-owned, so no organizational handoff is evidenced.
Only three commits from one active maintainer were observed in the last three months; this is some activity, but too little history to demonstrate sustained maintenance.
Composer build tooling is present, but no security scanning tools were detected, leaving an avoidable gap in automated security hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.