The repository has one active contributor, and all four workflow actions are unpinned. Its MIT licensing, substantial README, repository tests, and release notes provide useful transparency.
70%
Total Score
67
100
50
The repository is owned by an individual user rather than an organization, so the single-contributor concentration is not offset by visible organizational backing.
All eight commits in the last three months came from one contributor, giving the project a single-person bus factor and increasing continuity risk.
The repository has no security policy. This is a modest transparency gap for a package that runs as a Composer plugin, though the active repository and clear licensing provide some compensating context.
The sole workflow was fully analyzed with no untrusted checkout or script-injection findings, but all four action references are unpinned. The lack of a top-level permissions block is acceptable on its own; unpinned actions remain a supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.