It includes tests, a README, a changelog, and release notes, with only two runtime dependencies. The prerelease label and lack of a security policy leave modest documentation and process caveats.
84%
Total Score
100
100
88
75
The project uses Composer for builds, but no security scanning tools were detected. The missing scanner is a modest process gap rather than evidence of abandonment.
The linked repository has no security policy, leaving vulnerability reporting and response expectations unclear.
This is a prerelease (v3.6.1RC3), although prereleases make up only 15% of recent versions and the major line is otherwise stable. Pinning is appropriate if production stability matters.
The single workflow was fully analyzed with no untrusted checkouts, script injection, or audit findings. One of two action references is unpinned, which is a limited reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.