It includes repository tests, release notes, and Composer security scanning, with no install scripts. The single maintainer and six unpinned workflow actions leave more maintenance and build-integrity risk than a mature release.
64%
Total Score
83
88
67
The package was first released 0 days ago and has only three releases, clustered about 2 hours apart, so there is little evidence of sustained maintenance yet.
The repository records 0 commits and 0 active maintainers in the last 3 months. Because the package is brand new, this is partly explained by limited history, but it still provides no evidence of an established maintenance cadence.
No repository security policy is present, leaving vulnerability-reporting expectations undocumented for a library that processes contact data.
Version v0.2.1 is an unstable 0.x release, and the README explicitly says its public API may change before 1.0.
The only workflow was fully analyzed with no dangerous triggers, untrusted checkouts, or audit findings, but all 6 action references are unpinned, weakening build reproducibility and tamper resistance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sabre/vobject Version ^4.5.6 || ^5.0 | — | — |
symfony/validator Version ^7.4 || ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.