The repository is intact, the release is documented, and the package has clear licensing. Automated checks lack pinned action references and a security policy, limiting operational transparency.
70%
Total Score
83
100
88
67
This is the package's only release, published 227 days ago. That limited registry history makes long-term maintenance less proven, although the linked repository remains active.
All 114 recent commits came from one contributor, creating a real continuity risk. Organization ownership provides some backing, but no second active contributor is shown.
Composer is used for builds, but no security-scanning tooling is reported, leaving a modest transparency and maintenance gap.
The repository has no security policy, making vulnerability reporting and response expectations less clear.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both action references are unpinned, weakening build reproducibility and update safety.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
timber/timber Version ^2.0 | — | — |
symfony/string Version 7.0 | — | — |
doctrine/inflector Version ^2.0 | — | — |
upstatement/routes Version ^0.9.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.