It includes tests, a changelog, a clear README, and a small runtime dependency set. The organization-backed repository is intact, but its lack of security scanning and one unpinned workflow reference reduce confidence.
58%
Total Score
100
100
88
75
The package has made eight releases since December 2022, but none in roughly two years; this is a meaningful sign of slowing maintenance for a dependency.
Composer build tooling is present, but no security scanning tools were detected; that is a modest transparency and maintenance gap.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but its one action reference is unpinned; this is a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
open-feature/sdk Version ^2.0 | — | — |
open-telemetry/api Version ^0.0.17 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.