The repository includes tests and Psalm scanning, and its workflow scopes permissions read-only. All 15 workflow actions are unpinned, while maintenance is concentrated in one contributor and no security policy is published.
72%
Total Score
88
100
88
75
All 30 recent commits came from one contributor, creating a meaningful continuity risk; organization ownership provides some ability to hand maintenance off.
The repository name does not match the package name and the README mention could not be confirmed, so package ownership is somewhat less transparent; the mismatch may still reflect a subpackage or broader repository.
No repository security policy is present, leaving vulnerability-reporting expectations and handling less transparent.
Version 0.9.6 is not yet a stable major release, but it is not a prerelease and the recent prerelease share is limited to 25%.
The workflow uses read-only permissions and has no dangerous sinks or audit findings, but all 15 action references are unpinned, weakening build reproducibility and action supply-chain control.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0.0 | — | — |
psr/container Version ^2.0.0 | — | — |
psr/http-factory Version ^1.0.0 | — | — |
psr/simple-cache Version ^3.0.0 | — | — |
psr/http-server-middleware Version ^1.0.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.