The repository has tests, a clear README, a matching license, and Composer security scanning. Organization backing and a non-archived repository help, but the missing security policy leaves an important transparency gap.
68%
Total Score
100
100
94
67
This is a young package with one release, published 177 days ago, so there is not yet enough release history to demonstrate sustained maintenance. Its recent origin partly explains the limited history but does not remove the uncertainty.
No repository security policy was found, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 17 action references are unpinned. The workflow also lacks a top-level permissions block; that is acceptable on its own, while unpinned actions remain a build-integrity hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
ramsey/uuid Version ^4.9 | — | — |
purrphp/pure-collection Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.