The repository includes tests, release notes, security scanning, and readme documentation. Install and update hooks, a missing security policy, and a very recent project history warrant extra caution.
72%
Total Score
100
100
93
63
The package runs post-install and post-update Composer scripts. These hooks increase installation-time execution and supply-chain exposure, even though they may be functional for this extension.
The package is only 3 days old, despite 6 releases and a recent release within hours of collection. That shows active early development but provides little evidence of long-term stability.
The repository has no security policy. That is a transparency gap for a package whose extension worker runs inside a consumer project.
The single workflow was fully audited, uses read-only permissions, and pins all action references. Three high-confidence unpinned-tools findings are a reproducibility hygiene issue, not a severe dependency risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
carthage-software/mago Version ^1.47.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.