The package has a minimal runtime footprint and solid consumer documentation. Repository tests, a matching MIT license, and no install scripts or deprecation reduce adoption risk, while workflow hygiene remains incomplete.
65%
Total Score
75
100
86
67
This is the package's first and only registry release, published today, so there is no demonstrated long-term release history despite the active repository.
One contributor made all six recent commits, leaving maintenance highly concentrated and creating a meaningful continuity risk.
Composer build tooling is present, but no security-scanning tool was detected; for a new package this is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all four action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.