Validate schema.org JSON-LD graphs against the full vocabulary and optional rule profiles such as Google rich results.
72%
Total Score
caution
This is a well-documented first release, but it has no track record and weak GitHub Actions pinning.
This package is brand new, with one release and no established release cadence, so its maintenance history is unproven. The repository's organization backing and three merged pull requests provide some context but not a long-term track record.
No commits or active maintainers were recorded in the preceding three months. Because the package is only zero days old, this mostly reflects limited observation time rather than proven abandonment, but it leaves maintenance capacity unestablished.
Composer build tooling is present, but no security scanning tool was detected. The missing scanner is a modest transparency gap for a new package, not a severe supply-chain finding.
Version 0.1.0 is an early, non-stable major release, so API and behavior stability are not yet demonstrated. It is not marked as a prerelease, which is a modest compensating signal.
Both workflows were analyzed without high-confidence audit findings or untrusted checkouts, but all five action references are unpinned and one workflow grants top-level write access. Those are meaningful hygiene weaknesses, though no untrusted trigger currently reaches them.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.