Healthy and suitable to depend on. It has a long release history, recent releases, active commits from three contributors, substantial repository tests, and clear licensing; the main caveats are no security policy and unspecified workflow token permissions.
88%
Total Score
80
100
94
80
Only one registry account has publish access, which is a modest publishing bus-factor concern for a user-owned project, though repository activity shows three active contributors.
The registry namespace and repository are owned by the same individual user, so there is no organization-level maintenance handoff to offset the small maintainer base.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a transparency gap, though it is not by itself evidence of unsafe maintenance.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the active maintenance and test evidence provide some compensation.
The only workflow lacks a top-level token-permissions declaration. No workflow requests top-level write access, but explicit least-privilege permissions would provide stronger CI hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.