The repository has tests, a substantial README, an MIT license, and release notes for this version. A single maintainer, no security policy, and unpinned workflow actions reduce confidence in ongoing project hygiene.
64%
Total Score
50
92
75
One registry maintainer is a thin publishing base for a user-owned project, increasing continuity risk if that person stops maintaining it.
This is the only release, published 277 days ago, with no later release in the available history. That is a meaningful maintenance concern, though the package is still relatively young.
The repository had 0 commits and 0 active maintainers in the last 3 months, so there is no evidence of continuing maintenance after the initial release.
The repository has no security policy, leaving no documented process for reporting or handling vulnerabilities. This is a transparency gap, not evidence of a security flaw.
The workflow audit completed successfully with no high- or medium-confidence findings and no untrusted triggers or sinks, but all 4 of 4 action references are unpinned. That leaves avoidable build-integrity exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
psr/container Version ^2.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-message Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.