The workflows use read-only permissions but all six actions are unpinned, and the repository has no security policy or scanning. A clear README, release notes, license, and recent commits provide useful transparency.
63%
Total Score
75
100
78
50
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational handoff capacity to offset the concentrated maintainer base.
Only two releases appeared within the first day, so the project has not yet demonstrated a mature release track record. This is partly offset by 97 recent repository commits, but the package remains very new.
One contributor made all 97 commits in the last three months, creating a significant handoff and continuity risk for a new project.
The repository has no stars, forks, or watchers. This is weak supporting evidence for maturity, though popularity alone does not determine whether a small package is healthy.
Composer is used for builds, but no security-scanning tooling is reported, leaving less automated visibility into dependency and build risks.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.