It has a clear license, substantial documentation, repository tests, and a security policy. A single publisher and no security-scanning tooling leave less operational depth.
69%
Total Score
50
100
86
88
Only one registry account has publishing access, limiting visible publishing redundancy even though the repository itself is active and documented.
The repository is owned by an individual rather than an organization, so the single-publisher limitation is not offset by visible organizational backing.
The package is only 0 days old, with four releases arriving within roughly 1 hour, so it has not demonstrated long-term maintenance yet.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository-hygiene gap.
All five workflows were analyzed with no detected injection or secret-handling findings, and four use read-only permissions. However, all 36 action references are unpinned and one workflow grants top-level write access, creating a reproducibility and least-privilege caution.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^2.0 || ^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
google/protobuf Version ^4.33 || ^5.0 | — | — |
psr/http-client Version ^1.0 | — | — |
psr/http-factory Version ^1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.