It has a clear README, an MIT license, repository tests, a matching source repository, and no install-time scripts. The small dependency footprint is reassuring, but the single maintainer, absent recent commits, missing security policy, and unpinned workflow actions reduce confidence for long-term use.
65%
Total Score
50
100
94
67
One registry maintainer is consistent with a small user-owned project, but it leaves little visible publishing redundancy if that maintainer becomes unavailable.
The repository had zero commits and zero active maintainers in the last three months. This is a meaningful maintenance concern, although the recent release provides some compensating evidence.
Composer build tooling is present, but no security-scanning tool was detected. For a small package this is a hygiene gap rather than a severe dependency risk.
The repository has no security policy. That weakens vulnerability-reporting transparency, though it does not by itself indicate unsafe code.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all three action references are unpinned, leaving the workflow exposed to upstream action changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.