The repository has 91 commits in three months, tests, release notes, and a clear README. It has no security policy or scanning tooling, so transparency and process are limited.
72%
Total Score
100
79
50
The package is only 120 days old and has three releases, all within roughly four days, so its long-term maintenance record is still unproven.
Composer build tooling is present, but no security scanning tools were detected, leaving automated security oversight limited.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
Version 0.0.3 is not in a stable major series, which signals an immature API and a higher likelihood of breaking changes.
The workflow uses read-only permissions and has no reported dangerous findings, but 13 of 16 action references are unpinned, weakening build reproducibility and action supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^14.3 || 15.*@dev | — | — |
helhum/dotenv-connector Version ^3.2 | — | — |
cweagans/composer-patches Version ^1.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.