The package has a clear license, tests, release notes, and one runtime dependency. The repository is not archived and the package name matches the repository, supporting confidence in its maintenance ownership.
73%
Total Score
75
100
100
67
There were no commits and no active maintainers in the last 3 months. This is a meaningful maintenance concern, though it is partly offset by two releases in the last 12 months and a recent repository push.
The repository has no published security policy. This is a transparency gap for reporting vulnerabilities, though the presence of Psalm provides some compensating security tooling.
All 2 analyzed workflow actions are unpinned, which weakens build reproducibility and action supply-chain hygiene. The audit found no dangerous triggers, untrusted checkouts, script injection, or high-severity findings, and the lack of a top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.