The project is well documented and tested, with a recent release and a clear license. Maintenance depends on one recent contributor, and workflow actions are not pinned; no security policy or scanning is present.
82%
Total Score
70
100
94
83
Only one registry account has publish access. This is a modest publishing-resilience concern, though repository activity shows the project is still being maintained.
All recent repository commits came from one contributor, so maintenance continuity is concentrated in a single person; the recent release provides some compensating evidence.
There was one commit in the last 3 months from one active maintainer, showing recent activity but a limited maintenance pace.
Composer build tooling is present, but no security-scanning tool was detected, leaving repository-level security hygiene less visible.
The repository has no security policy, so there is no documented channel or process for reporting vulnerabilities.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.