Clear documentation, tests, licensing, and a long release history support dependable adoption. Maintenance is currently concentrated in one contributor, while workflow actions are all unpinned; the low-confidence cache warning is an additional hygiene concern.
68%
Total Score
50
100
100
75
The registry namespace and repository are owned by the same individual, and the owner type is User; this supports ownership continuity but provides no organizational maintenance backup.
One contributor made all 3 commits in the last 3 months, leaving maintenance dependent on a single active contributor; the repository is user-owned, so there is no organizational handoff evidence to offset this.
Only 3 commits were recorded in the last 3 months, indicating relatively sparse recent development despite the recent release history.
The repository has no security policy, which is a transparency gap for reporting and handling vulnerabilities.
All 5 workflows were analyzed with no untrusted checkouts or script injection, and none grants top-level write access. However, all 15 action references are unpinned, and the auditor reported a low-confidence high-severity cache-poisoning pattern; this warrants workflow hygiene caution rather than a severe verdict on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
brick/math Version ^0.14|^0.15|^0.16|^0.17|^0.18 | — | — |
symfony/yaml Version ^7.4|^8.0 | — | — |
symfony/console Version ^7.4|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.