Clear documentation, tests, release notes, and a matching repository make adoption easier. The small project footprint and workflow hygiene leave less room for recovery or review as usage grows.
68%
Total Score
75
88
50
All 47 recent commits came from one contributor, leaving a concentrated maintenance dependency and limited continuity if that contributor becomes unavailable.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and review gap.
The repository has no security policy, so the process for reporting and handling vulnerabilities is not documented.
Version 0.3.1 is not a stable major release, so compatibility expectations are lower, although it is not marked as a prerelease.
All four workflows grant top-level write permissions and all 29 action references are unpinned. The audit found no untrusted checkout or script-injection path, so this is workflow hygiene risk rather than a severe finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/simple-cache Version ^3.0 | — | — |
orieg/judy-polyfill Version ^2.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.