The MIT license, repository tests, release notes, and pinned workflow actions provide useful transparency. The project is small and has limited security-process evidence, so pin this version while watching for renewed maintenance.
65%
Total Score
75
100
83
83
The package is young, with 5 releases over 151 days and a rapid initial cadence, but the latest release was about four months before collection. That pause is a maintenance concern for a tooling package.
No commits and no active maintainers were observed in the last three months. Combined with the release pause, this indicates a thin or currently inactive maintenance pattern.
The repository has zero stars, forks, and watchers. This provides little external validation, but popularity is supporting evidence only and does not outweigh the maintenance and transparency signals.
Composer is used for the build, but no security-scanning tooling is reported. The missing scanning is a modest process gap rather than evidence of unsafe code.
The repository has no security policy. For a code-quality tool that can execute project and build commands, this weakens vulnerability-reporting transparency.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.