The package includes tests, release notes, a clear license, and recent quality-focused maintenance. One contributor made all 39 recent commits, while the absent security policy and seven unpinned workflow actions leave meaningful maintenance and build-hygiene concerns.
72%
Total Score
83
100
100
50
The package runs post-install and post-update Composer scripts. These add install-time execution surface and deserve review, although this signal alone does not show harmful behavior.
All 39 recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some handoff capacity, but no second active contributor is shown in this period.
The repository has no security policy, leaving vulnerability-reporting and response expectations undocumented.
The single workflow was fully analyzed, uses read-only permissions, and has no detected dangerous sinks or audit findings. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.