The package is small, clearly licensed, and has a matching source repository with minimal runtime dependencies. Its latest release was two years ago, recent commit activity is absent, and no security policy is provided. Pin this version if its narrow PHP helper scope fits.
61%
Total Score
50
100
93
67
One registry maintainer is consistent with a small user-owned project, but it leaves little observable publishing redundancy. The matching repository ownership provides some accountability.
Only three releases exist, and none were published in the last 12 months; the latest release was about two years ago. This indicates weak ongoing maintenance, though it does not by itself show abandonment.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the long release gap. The repository is not archived, which provides limited compensation.
The linked repository has no security policy, reducing transparency for reporting and handling vulnerabilities. The package is small, but this remains a genuine maintenance and governance gap.
The single workflow was fully analyzed with no audit findings or untrusted checkout and injection risks. However, all three action references are unpinned, leaving avoidable dependency-integrity exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.