The project includes clear documentation, tests, a changelog, and a permissive license. Pin workflow actions and add a security policy to improve reproducibility and disclosure.
86%
Total Score
67
94
75
The package and repository are owned by the same individual account, so the project is directly aligned but lacks organizational handoff capacity.
Three contributors were active, but the top contributor made 80% of recent commits, leaving maintenance substantially concentrated in one person.
Composer is used as a build tool, but no security scanning tools were detected; this is a modest transparency and maintenance gap.
The repository has no security policy, so there is no documented route for reporting or coordinating vulnerability fixes.
All four workflows were analyzed without failed files, dangerous sinks, or audit findings, and permissions are not broadly writable. However, all nine action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.