The package is MIT-licensed, lightweight, and has only one runtime dependency. Its short history, missing security policy and scanning, and six unpinned workflow actions leave avoidable maintenance and build-integrity gaps.
72%
Total Score
100
100
79
50
Eleven releases in 48 days and a median interval of about 17 hours show strong current activity, but the project is still very young, so long-term maintenance is not yet established.
Composer build tooling is present, but no security-scanning tool was detected. That leaves a modest transparency and maintenance gap.
The repository has no security policy. For a library intended for application integration, this makes vulnerability reporting and response expectations less clear.
Version 0.7.0 is not a stable major release, and the README warns that minor versions may change the API. This is a real compatibility caveat for library consumers.
The sole workflow was fully analyzed with no injection or high-severity findings, and it has no top-level write permissions. However, all 6 action references are unpinned, weakening build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.