It includes tests, release notes, a license file, and a security policy. Frequent releases and organization ownership provide useful support, but the pre-1.0 version signals limited maturity.
67%
Total Score
88
100
89
88
All 21 recent commits came from one contributor. Organization ownership offers some handoff capacity, but no second active contributor is shown to reduce this concentration.
Composer is used for builds, but no security scanning tool was detected, leaving a modest security-process gap.
Version 0.22.0 is not a stable major release, so the API may still change even though it is not marked as a prerelease.
All workflows were analyzed successfully and avoid untrusted checkouts and script-injection triggers, but all six action references are unpinned and the release workflow has two high-confidence template-injection findings. These are workflow hygiene concerns rather than a standalone severe health failure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.