The organization provides some continuity, and the repository had 10 commits in the last three months. All four workflow actions are unpinned and one contributor made every recent commit; the missing security policy adds a smaller transparency gap.
68%
Total Score
83
93
50
One contributor made all 10 commits in the last three months, leaving maintenance concentrated in a single person. Organization ownership provides some handoff capacity, but no second active contributor is shown.
Composer is used as a build tool, but no security scanning tooling was detected, leaving dependency and build-risk checks less visible.
The repository has no security policy, which reduces transparency for reporting and handling vulnerabilities.
The workflow audit covered the only workflow completely and found no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all four referenced actions are unpinned, creating a workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.