The repository includes tests and release notes, and the package has no runtime dependencies. Its security policy is absent, while the README documents known issues and unfinished work; one workflow also has a high-confidence template-injection finding.
68%
Total Score
100
88
67
This is the first and only release, published less than a day ago, so there is no track record for maintenance or release stability yet. Its age makes the lack of later activity inconclusive rather than evidence of abandonment.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and hygiene gap, not evidence that the package is unsafe.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented. This lowers transparency for a package intended for dependency use.
All seven workflows were analyzed with no untrusted checkout or script-injection findings; four of thirteen action references are unpinned. A high-confidence template-injection finding is a workflow hygiene concern, but it is not corroborated by a dangerous trigger or sink in the reported paths.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.