Recent work from two contributors and organizational ownership reduce abandonment risk. The package is licensed, documented, and has no install-time scripts, but its limited release history and workflow audit findings merit caution around future releases.
72%
Total Score
100
100
83
67
The package is only 205 days old with two releases and a median interval of about 175 days, so its maintenance record is still limited rather than mature.
The repository has one star and no forks, offering little community validation; this is supporting evidence only and does not outweigh the active organizational ownership.
The repository uses Composer build tooling, but no security-scanning tools were detected, leaving a modest process gap.
No repository security policy was found, reducing transparency about how maintainers handle vulnerability reports.
Both workflows were fully analyzed, use three pinned actions, and have no untrusted checkouts or script-injection findings. However, the release workflow contains five high-confidence template-injection findings, which weaken release-process hygiene even without a dangerous trigger being reported.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.