The package is small and clearly identified, with a matching repository, MIT licensing, and a focused dependency set. Its last release and commit activity were about two years ago, while the workflow uses three unpinned actions; pin a maintained version if ongoing updates matter.
58%
Total Score
50
100
88
75
The latest release was about two years ago, and there were no releases in the preceding 12 months of the collected history. This lowers confidence in ongoing maintenance, despite the package having 20 releases overall.
The repository had no commits and no active maintainers in the last three months. Together with the release gap, this is a meaningful abandonment concern.
Composer build tooling is present, but no security scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no SECURITY.md or other detected security policy, leaving vulnerability-reporting expectations unclear.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all three action references are unpinned. Unpinned actions weaken build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.