This is a healthy, actively maintained release with strong recent publishing activity, a stable non-prerelease version, an unarchived repository, substantial repository popularity, and current commit activity from two contributors. The package and repository are transparently licensed, include repository tests, use straightforward Composer tooling, and show no dangerous workflow patterns or install-time lifecycle scripts. The main reservations are the absence of a repository security policy and undeclared top-level GitHub Actions token permissions, plus a single registry publisher account; these are hygiene and continuity concerns rather than evidence of abandonment, especially given the recent releases and two active contributors.
86%
Total Score
100
100
94
80
Composer build tooling is present, but no security-scanning tools were detected. The missing scanning is a security-hygiene gap, though it is not evidence of poor maintenance on its own.
The repository has no security policy. This weakens vulnerability-reporting transparency and response expectations, creating a genuine but limited hygiene concern.
The only workflow lacks top-level token permissions, and no workflow declares read-only permissions. Although no write permissions were observed, explicit least-privilege configuration would be safer.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.