Documentation, tests, a changelog, and a matching MIT license make the release straightforward to evaluate. The project is small and lacks a security policy, so maintenance depends on a narrow public process.
78%
Total Score
100
86
75
The project uses Composer build tooling, but no security scanning tools were detected. The missing scanning reduces assurance modestly, though it does not by itself indicate abandonment or unsafe code.
The repository has no security policy, leaving vulnerability reporting and handling expectations undocumented. This is a transparency gap for a native extension project.
This is a non-prerelease v0.x release, so the pre-1.0 major version leaves greater room for breaking changes. The absence of recent prereleases is a modest compensating sign.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or high-severity audit issues, and it scopes permissions at job level. However, all 9 action references are unpinned, weakening build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.