Usable with caveats: the release is clearly packaged, tested, licensed, and backed by a matching repository, but it is newly published with no established maintenance record. The repository also lacks a security policy and explicit workflow permissions, so adoption should wait for more project history if this is a critical dependency.
68%
Total Score
50
100
88
80
This is the package's first release and it was published less than 1 hour ago, so there is no demonstrated release cadence or long-term maintenance history. The repository's tests and release automation provide some early evidence of project activity.
There were no commits or active maintainers during the last 3 months, but the repository is newly created and was pushed about 1 hour ago. This remains insufficient evidence of sustained maintenance rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. The limited tooling is acceptable for a small new package, though it leaves security and maintenance checks less transparent.
The repository has no security policy. That is a transparency gap for reporting vulnerabilities, although the package's small scope and included tests provide some compensating project hygiene.
The only workflow lacks top-level permissions and uses job-level permissions without declaring read-only permissions. No write permissions were found, but explicit least-privilege settings would make the CI configuration safer and clearer.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.