The package includes clear documentation, tests, and a license. Its small contributor pool and unpinned workflow actions warrant routine monitoring.
76%
Total Score
83
100
88
75
The package is only 52 days old and has 11 releases, with a median interval of about 3 hours. This shows active early development but leaves limited evidence of long-term stability.
Two contributors are active, but one accounts for 80% of the 10 commits in the last 3 months. The organization backing provides some handoff capacity, but contributor concentration remains a minor concern.
Composer build tooling is present, but no security-scanning tool was detected. This is a modest transparency and maintenance gap, not evidence of an unsafe release by itself.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
All three workflows were analyzed successfully with no injection, untrusted-checkout, or high-severity findings. However, all 3 of 3 action references are unpinned, reducing build reproducibility and supply-chain protection.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
filament/filament Version ^5.1 | — | — |
liberusoftware/organizations-teams Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.