Organization backing, repository tests, clear documentation, and an MIT license provide solid support. The release remains suitable for consideration, but its maintenance capacity is narrower than ideal.
72%
Total Score
83
100
94
83
One contributor made 100% of the 6 commits in the last 3 months. Organizational backing partly reduces handoff risk, but the current maintenance activity is still concentrated in one person.
Composer build tooling is present, but no security-scanning tooling was detected. The missing automated security coverage is a modest transparency and maintenance gap.
The repository has no published security policy. This leaves disclosure and response expectations unclear, although it does not by itself indicate that the package is unsafe.
Both workflows were analyzed completely with no dangerous triggers, untrusted checkouts, script injection, or audit findings, and one workflow uses read-only permissions. However, all 3 action references are unpinned, leaving build behavior less reproducible and increasing update risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
toflar/fast-set Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.