The release has strong documentation, tests, release notes, an MIT license, and organization backing. Maintenance evidence is thin after the initial burst, and all three workflow action references are unpinned; the project also lacks a security policy.
62%
Total Score
75
100
75
75
The package is 107 days old with three releases, all published within about four hours, and no later releases were observed. This shows an initial release burst but not sustained release activity.
The repository recorded zero commits and zero active maintainers during the last three months. Combined with the short release burst, this is meaningful evidence of currently limited maintenance.
The project uses Composer, but no security scanning tools were detected. That is a transparency and maintenance gap, though it does not by itself make the release unfit.
The repository has no security policy. For a client handling API credentials and network requests, the absence reduces transparency around vulnerability reporting.
Version v0.2.1 is not a prerelease, but the 0.x major version signals an API that may still change and a relatively immature package.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.