The package is documented, organized, and backed by an organization, with a stable v1.0.0 and release notes. Its workflow references are unpinned, and the repository has neither security scanning nor a security policy.
60%
Total Score
75
100
88
67
This is the only release, published nearly two years ago, with no releases in the last 12 months. That leaves limited evidence of ongoing maintenance for a package intended as an API dependency.
There were no commits and no active maintainers in the last three months. The repository was last pushed in May 2025, so current maintenance capacity is uncertain.
Composer is used for builds, but no security scanning tools are configured. That is a transparency and maintenance gap for a dependency published to a registry.
The repository has no security policy. This does not show a vulnerability, but it provides no documented route for reporting or handling security issues.
The workflow audit completed successfully with no dangerous findings, but both analyzed action references are unpinned. The workflow has no top-level permissions block, which is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.