Clear usage documentation, tests, release notes, and a minimal runtime dependency make this straightforward to evaluate and adopt. Its single-user ownership and limited repository visibility leave less oversight than a mature alternative.
70%
Total Score
50
100
89
67
There were no commits and no active maintainers in the last three months. The recent release is compensating evidence, but the current development pause still lowers maintenance confidence.
The repository has one star and no forks, providing little independent evidence of community review or adoption. Popularity is supporting evidence rather than a verdict, so this is a modest concern.
Composer build tooling is present, but no security scanning tools were detected, leaving less automated visibility into repository changes.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
The workflow audit completed successfully and found no dangerous sinks or audit findings, but all six action references are unpinned. That leaves the build exposed to mutable action changes and is a workflow hygiene concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.