The repository includes tests and the package is clearly licensed. Its single release in the last year, no recorded commits in three months, and unpinned workflow actions reduce confidence in ongoing care.
68%
Total Score
50
83
50
The package has five releases over about two and a half years, but only one release in the last 12 months and a median interval of about 122 days indicate a slow cadence.
No commits and no active maintainers were recorded in the last three months, which is a meaningful sign of limited recent maintenance.
The repository uses Composer but has no detected security-scanning tooling, leaving a modest transparency and maintenance gap.
The repository has no security policy, so it does not document a clear process for reporting and handling vulnerabilities.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.