The project has solid documentation, tests, release notes, licensing, and a security policy. Its very recent history and zero commits in the last three months leave maintenance depth less proven, while unpinned workflow actions are a minor hygiene concern.
78%
Total Score
67
100
88
88
One registry maintainer is consistent with a user-owned project, but it leaves a limited publishing fallback if that maintainer becomes inactive.
Eight releases in roughly six months, all within the last year, show active early development, although the short project history limits evidence of long-term maintenance.
The repository recorded zero commits and zero active maintainers in the last three months; despite recent releases, sustained maintenance is not yet demonstrated.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest transparency and maintenance gap.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all three action references are unpinned, which is a minor workflow hygiene weakness.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.