Healthy and suitable to use. It has a long release history, frequent recent releases, active commits from two contributors, tests, release notes, and automated build and dependency tooling. The repository lacks a security policy and explicit workflow token permissions, but its workflows show no detected dangerous patterns.
90%
Total Score
88
100
94
75
The package and repository are owned by the same individual account, which is consistent ownership but offers less organizational continuity than an organization-backed project.
No security policy was found in the repository, leaving vulnerability-reporting guidance unclear; the active project and Dependabot scanning partly compensate but do not remove this transparency gap.
Neither workflow declares top-level GitHub Actions token permissions. No workflow requests top-level write access, but explicit least-privilege settings would provide stronger assurance.
Version 0.13.0 is not a stable major release, but it is not a prerelease and recent releases contain no prerelease versions, so the maturity concern is limited.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
mcp/sdk Version ^0.8 | — | — |
psr/log Version ^3.0 | — | — |
dg/rss-php Version ^1.2 | — | — |
symfony/console Version ^6.0 || ^7.0 | — | — |
symfony/process Version ^6.0 || ^7.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.