Documentation, tests, and a security policy are present, and the organization-backed repository is active. The build uses three unpinned workflow actions and lacks security-scanning tooling; maintenance history remains too short to establish maturity.
67%
Total Score
100
100
79
83
This is the package's first release, published today, so there is no release cadence or history demonstrating sustained maintenance. The repository is active and well documented, but that does not replace production track record.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest repository hygiene gap rather than evidence of abandonment.
Version 0.4.1 is not a stable major release, which signals an API that may still change. It is not marked as a prerelease, providing some compensation.
All three analyzed action references are unpinned, and one workflow grants top-level write permissions. The audit found no untrusted checkout, script injection, or other high-confidence dangerous workflow finding, so this is a hygiene caution rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.