Clear documentation, tests, and a matching repository make adoption easier. The project is young and maintained by one active contributor, while workflow references are unpinned.
67%
Total Score
50
88
50
One contributor made 100% of the 3-month commit activity, leaving no demonstrated backup maintainer if that contributor becomes unavailable.
There were 2 commits from 1 active maintainer in the last 3 months. Recent work is present, but the low volume provides only limited evidence of sustained maintenance capacity.
The repository has no security policy. For a code generator that may process API specifications and produce application code, this reduces transparency for reporting vulnerabilities, though it is not evidence of unsafe code.
Version 0.1.7 is not marked prerelease, but the 0.x major version signals an immature API with potentially more breaking changes ahead.
The single workflow was fully analyzed with no untrusted checkout or script-injection findings, but all 3 action references are unpinned. That weakens build reproducibility and supply-chain hygiene without showing an active exploit path.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
symfony/console Version ^7.0|^8.0 | — | — |
maxbeckers/php-yaml-parser Version ^0.5.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.