Clear licensing, documentation, tests, and release notes support predictable use. The repository is organization-backed and current, though recent work is concentrated in one contributor and workflow actions are unpinned.
82%
Total Score
75
100
94
100
All recent commit activity came from one contributor, creating concentration risk; organization backing provides some capacity for handoff but does not remove the recent single-contributor pattern.
Only one commit was recorded in the last 3 months, indicating limited recent implementation activity despite the current release and recent merged pull requests.
Composer is used for the build, but no security-scanning tools were detected. For this package, the established build tool is positive while the missing scanning coverage is a minor transparency gap.
The single workflow was fully analyzed with no untrusted checkouts, script injections, or audit findings. However, all 3 action references are unpinned, leaving avoidable supply-chain reproducibility risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.