A security policy, tests, release notes, and a matching organization-backed repository improve transparency. Maintenance has been quiet since April, and every workflow action is unpinned, so this young pre-1.0 library deserves continued monitoring.
64%
Total Score
75
100
81
88
The package is only 157 days old with three releases, all clustered within about 4 hours, so its release history is too short to demonstrate durable maintenance.
There were no commits and no active maintainers in the last three months; for a young library, that is a meaningful maintenance concern despite the recent release history.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
Version v0.1.1 is not a stable major release, which indicates an early API and a higher likelihood of breaking changes than a mature 1.x package.
The only workflow was fully analyzed with no dangerous audit findings or untrusted checkouts, but all 6 action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.