The package has a clear README, tests, MIT licensing, and no install-time scripts. Its small maintainer base, absent security scanning, and unpinned workflow actions add modest maintenance and build-hygiene concerns.
78%
Total Score
67
100
94
100
Only one registry publishing account is listed, leaving a thin publishing base and increasing dependence on a single maintainer.
There were no commits or active maintainers in the last three months. The recent release and matching repository push partly compensate, but ongoing development activity is currently limited.
Composer is used for the build, but no security scanning tool is configured. For a small validation library this is a modest transparency and maintenance gap, not evidence of unsafe behavior.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving avoidable build-integrity risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.