The package includes tests, a clear license, and release notes for this version. Its organization-backed repository matches the package and remains active, but workflow references are not pinned.
72%
Total Score
83
100
88
67
The project has existed for about eight years but has only four releases, with a typical gap of about 11 months; one release in the last year shows it is not abandoned, but maintenance is infrequent.
All two recent commits came from one contributor, leaving maintenance dependent on a single active person; organization backing provides some capacity for handoff but does not remove the concentration concern.
Composer build tooling is present, but no security scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, so users have no documented reporting path for vulnerabilities.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mossadal/math-parser Version ^1.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.