The package has clear usage documentation, release notes, tests, and a modest but active contributor base. Pin workflow action references before relying on its CI supply chain.
82%
Total Score
75
100
89
63
A post-autoload-dump script runs during installation. This is a potentially relevant install-time behavior, but the signal provides no evidence that it is unsafe or unusually broad.
The repository is owned by an individual account rather than an organization, so maintenance depends on a relatively small personal project base; recent activity and two contributors provide partial compensation.
Two contributors are active, with the leading contributor responsible for about 62% of recent commits. This is somewhat concentrated but not a single-contributor project.
The repository has only 2 stars and no forks, so external adoption evidence is limited. Popularity is supporting evidence rather than a requirement, and active release and commit signals compensate for this.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency gap, offset by the repository's tests and CI workflows.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.