It is MIT-licensed, documented, tested, and backed by an organization-owned repository. Maintenance evidence is thin, while the CI workflow needs tighter dependency pinning.
61%
Total Score
75
88
50
Only two releases have appeared over about eight months, with roughly four months between releases. That is limited maintenance evidence for a relatively young package, though it is not abandonment by itself.
The repository recorded no commits and no active maintainers in the last three months. For a package with only two releases, this is a meaningful maintenance warning.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no SECURITY.md or other security policy, leaving vulnerability reporting expectations unclear.
The workflow audit completed cleanly with no dangerous triggers, untrusted checkouts, or audit findings, but all 9 action references are unpinned. That leaves CI exposed to unexpected action changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
amphp/amp Version ^2.4 | — | — |
amphp/process Version ^1.1 | — | — |
webmozart/glob Version ^4.4 | — | — |
symfony/filesystem Version ^5.0|^6.0|^7.0|^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.