Healthy and suitable to depend on, with one meaningful maintenance concern: all recent commits came from a single contributor. The organization-backed repository is active, releases are frequent, and the project has strong testing and security tooling.
82%
Total Score
75
100
100
75
One contributor made all 16 commits in the last three months, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second recently active contributor is shown.
There were 16 commits in the last three months, so development has not stopped. However, all recent activity came from one active maintainer, leaving limited observable contributor depth.
No repository security policy was found, which is a transparency gap for reporting vulnerabilities. The presence of Gitleaks and CodeQL partially supports security practice but does not replace a disclosure policy.
Most workflows use read-only permissions, but two omit top-level permissions and three declare top-level write access. This is a modest CI hardening concern rather than a severe risk, especially alongside the clean workflow analysis.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3 | — | — |
drush/drush Version ^11||^12||^13 | — | — |
symfony/yaml Version ^6||^7 | — | — |
vlucas/phpdotenv Version ^4||^5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.