The project has five active contributors and a clear MIT license. Its workflows have no detected dangerous findings, though all nine action references are unpinned.
82%
Total Score
100
100
88
67
The package has had no registry release in the last 12 months, and its latest release was over two years ago, which raises version freshness and abandonment concerns. Active repository commits partly compensate for the stale registry cadence.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations unclear. This is a maintenance and transparency gap, not evidence that the release is unsafe.
All four workflows were analyzed successfully with no dangerous audit findings, no untrusted checkouts, and no script injection. However, all nine action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.