Clear documentation, repository tests, and a small dependency surface reduce adoption friction. Maintenance has been quiet for about 16 months, and all six workflow action references are unpinned; the missing security policy adds a smaller transparency concern.
67%
Total Score
75
100
88
83
The package has existed since 2013 with 13 releases, but there were no releases in the 12 months before collection and the latest release was about 16 months earlier. This indicates a mature but currently quiet project.
There were no commits and no active maintainers in the three months before collection, consistent with roughly 16 months since the latest release. This lowers confidence in prompt maintenance, though the package remains mature and stable.
The repository uses Composer and Make for builds, but no security scanning tools were detected. The established build tooling is positive; the missing scanning is a modest hygiene gap.
The repository has no security policy. This does not establish a vulnerability, but it reduces transparency about how security issues are reported and handled.
Both workflows were analyzed successfully and have no detected dangerous sinks or audit findings. However, all six action references are unpinned, leaving workflow behavior exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.