Usable with caveats: it is a newly published, well-scaffolded package with tests, a clear license, and organizational backing, but it has no demonstrated maintenance history yet and lacks security-policy and workflow permission hardening.
68%
Total Score
83
100
81
80
This is the first release and the package is less than one day old, so there is no evidence yet of sustained release maintenance or long-term stability.
There were no commits and no active maintainers in the preceding three months; because the repository is newly created, this primarily reflects limited history, but it leaves maintenance capacity unverified.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-process gap for a package that handles API credentials and fiscal data.
No repository security policy was found, reducing transparency about vulnerability reporting and response expectations.
The only workflow does not declare top-level token permissions. No write permissions were detected, but explicit least-privilege settings would provide stronger workflow hardening.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.