The package includes tests, clear documentation, release notes, and a lightweight dependency profile. Workflow references are unpinned, and the repository has no security policy or scanning, leaving maintenance and build-hygiene gaps.
70%
Total Score
83
100
88
75
The project has existed for about five years and released twice in the last 12 months, but its median release interval is about 342 days, indicating a slower cadence.
All five recent commits came from one contributor, creating concentration risk; organizational ownership provides some handoff capacity but no second active contributor is shown.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
The repository has no security policy, which makes vulnerability-reporting expectations less clear for consumers.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned, weakening build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.