The repository has no security policy or security scanning, and both workflow actions are unpinned. Clear documentation, tests, a changelog, and an MIT license make the package easier to evaluate.
62%
Total Score
50
100
88
50
This is the package's only release, published 216 days ago, so there is little release history to demonstrate sustained maintenance.
There were zero commits and zero active maintainers in the past three months. For a package released only once, this leaves maintenance and abandonment risk unresolved.
Composer build tooling is present, but no security scanning tools were detected. That is a modest transparency and maintenance gap rather than evidence that the package is unsafe.
The repository has no security policy. For an SDK handling an external SMS API, the missing disclosure and reporting process lowers project transparency.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.