The package is well documented, tested, MIT-licensed, and has no install-time scripts. Its CI uses two unpinned actions, while the project is too new to demonstrate sustained maintenance or provide a security policy.
62%
Total Score
50
83
75
The package has only three releases, all published on its first day, so there is no meaningful release history or evidence of sustained maintenance yet.
No commits or active maintainers were recorded in the prior three months. Because the package is only hours old, this primarily reflects limited history, but it still leaves maintenance capacity unproven.
The repository has no security policy. This is a transparency and response-process gap for a package that exercises application requests, although it is not an abandonment signal by itself.
Version 0.2.0 is not a prerelease, but the 0.x major version indicates the API may still change substantially as the newly published project matures.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its action references are unpinned, leaving avoidable build-reproducibility and action-substitution exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.0|^8.0 | — | — |
illuminate/http Version ^12.0|^13.0 | — | — |
opis/json-schema Version ^2.6 | — | — |
illuminate/console Version ^12.0|^13.0 | — | — |
illuminate/routing Version ^12.0|^13.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.