The package includes clear documentation, tests, a license, and an active organization-backed repository. Recent repository work is limited to two commits from one contributor, and all 16 workflow actions are unpinned.
70%
Total Score
63
100
94
100
All recent commits came from one contributor, creating a concentrated maintenance dependency. Organization ownership partly offsets handoff risk, but no second recent contributor is shown.
Only two commits were made in the last three months by one active maintainer. This is genuine recent activity, but the low volume weakens confidence in ongoing maintenance.
There are 10 open issues but no issues or pull requests were opened or closed in the last month, providing little evidence of active issue maintenance.
The project uses Make and Composer, which supports reproducible project workflows, but no security scanning tools were detected.
The sole workflow was fully analyzed with no untrusted checkout, script-injection, or high-confidence audit findings. However, all 16 action references are unpinned, which leaves workflow dependencies exposed to mutable upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
composer/installers Version ^2|^1.0.1 | — | — |
param-processor/param-processor Version ~1.10 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.