A security policy and release notes improve transparency for maintainers and consumers. The workflow leaves all six actions unpinned, and no commits landed in the last three months, so build reproducibility and maintenance deserve attention.
78%
Total Score
75
100
94
100
No commits or active maintainers were recorded in the last three months, which is a maintenance caution. The same-day repository push and release history partly offset the concern but do not erase the recent inactivity.
The repository uses Composer build tooling, but no security-scanning tools were detected. For a small package this is a modest transparency and hygiene gap rather than a severe risk.
The single workflow was fully analyzed with no high-confidence audit findings or unsafe triggers, but all six action references are unpinned. Unpinned actions weaken build reproducibility and deserve caution.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.