Healthy and actively maintained, with clear documentation, licensing, and organization backing. The main caveat is that all 14 commits in the last three months came from one contributor, and the workflow does not declare top-level token permissions.
82%
Total Score
88
100
88
83
One contributor made all 14 commits in the last three months, creating a genuine continuity risk; organization backing provides some ability to hand maintenance off but does not remove the present concentration.
The repository uses Composer and Robo for builds, but no security scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence of unsafe code.
The only workflow lacks top-level token permissions, so its default permission scope is less explicit than preferred; it declares no top-level write permissions.
Version 0.14.1 is not a stable-major release, but it is not a prerelease and recent releases contain no prerelease versions, so the maturity concern is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
joomla/github Version ~2|~3|~4 | — | — |
consolidation/robo Version ^5.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.