The package is clearly licensed, documented, tested in the repository, and matched to its source repository. Its CI workflow is fully analyzed and has no detected dangerous findings, but external actions are unpinned and security scanning is absent.
68%
Total Score
50
79
75
This is the package's first release, published today, so there is no release track record yet. That limits confidence about sustained maintenance but does not indicate abandonment on its own.
No commits or active maintainers were observed during the last three months, but the repository and release are only hours old. This is an important coverage limitation rather than evidence of a collapsed project.
Composer build tooling is present, but no security scanning tools were detected. That is a hygiene gap for a package intended to process application data, though it is not evidence of unsafe code.
Version v0.1.0 is an early non-stable-major release, which signals limited maturity and possible API change risk. It is not marked as a prerelease, providing a small counterpoint.
The single workflow was fully analyzed with no dangerous audit findings or untrusted checkout and script-injection paths. Both external action references are unpinned, leaving a modest supply-chain hygiene weakness.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.