The MIT license, zero runtime dependencies, repository tests, and 28 recent commits are reassuring. Long-term maintenance is unproven, ownership is concentrated in one contributor, and the workflow audit found a high-confidence template-injection issue.
58%
Total Score
75
100
86
67
This is a brand-new package with one release and no established release interval, so maturity and long-term maintenance remain unproven.
All 28 recent commits came from one contributor, leaving maintenance highly dependent on a single person.
Composer build tooling is used, but no security scanning tool was detected, leaving a modest transparency and detection gap.
The repository has no security policy, so there is no documented process for reporting or handling vulnerabilities.
All seven workflows were analyzed, with no untrusted checkout or script-injection trigger, but one workflow has a high-confidence template-injection finding and four of 13 action references are unpinned.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.