The package has a clear API surface and predictable installation requirements. Its main weakness is workflow dependency pinning, which warrants routine CI review.
82%
Total Score
100
100
94
75
The project uses Composer and has repository tests and CI-related files, although no security-scanning tool was detected. The missing scanner is a minor transparency gap rather than evidence of abandonment.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented. This is a modest transparency gap, partly offset by the active repository and tested release.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkout or script-injection findings. However, all 4 of 4 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.