Clear documentation, tests, and a recent release make integration straightforward. The project has no security policy, and all three workflow actions are unpinned, while ongoing work is concentrated in one contributor.
68%
Total Score
75
100
86
75
The package has only 3 releases across about 3 years, with a median interval of about 18 months; however, 2 releases arrived in the last 12 months and the latest was published recently.
All 4 recent commits came from one contributor, leaving maintenance highly dependent on a single person and creating a meaningful continuity risk.
Composer build tooling is present, but no security scanning tools were detected, leaving repository-level security hygiene less developed.
The repository has no security policy, making the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed with no audit findings or untrusted execution paths, but all 3 action references are unpinned, so their exact revisions are not fixed.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.