Strong documentation, repository tests, and an active organization-backed project improve confidence. The release is very new, depends on one contributor, and uses two unpinned workflow actions.
68%
Total Score
75
79
75
The package was released today and has only two releases, so there is too little history to establish long-term maintenance reliability.
All 13 commits in the last three months came from one contributor, creating a concentrated maintenance dependency; organization backing provides some handoff capacity.
Composer build tooling is present, but no security-scanning tooling was detected, leaving a modest transparency and maintenance gap.
Version v0.1.1 is pre-1.0, which indicates an early-stage API and greater compatibility risk despite not being marked as a prerelease.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both referenced actions are unpinned, reducing build reproducibility and supply-chain assurance.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.