The package includes a substantial README, tests, MIT licensing, and a lean dependency set. The repository has no recent commits, no security policy, and its three workflow actions are unpinned.
72%
Total Score
50
100
94
67
One registry publishing account is listed. That is a limited publishing base, but the linked repository is owned by the same individual, so it is not an unexplained mismatch.
The repository recorded zero commits and zero active maintainers in the last three months. This weakens evidence of ongoing development, although the frequent recent registry releases partly compensate.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy. For a library that parses and sends HL7 data, the missing vulnerability-reporting guidance reduces maintenance transparency.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. The lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.