It has a usable README, repository tests, a license, and a security policy. Its very short history leaves maintenance capacity unproven; pin this version and reassess after a longer release and commit record.
65%
Total Score
50
83
100
The package is only 2 days old with 3 releases, so active early publishing is visible but long-term maintenance is unproven.
All recent commits come from one contributor, leaving maintenance dependent on a single person; the user-owned project provides no shown organizational handoff capacity.
The repository shows 1 commit in the last 3 months from 1 active maintainer; this is consistent with the package's recent launch but provides little evidence of sustained maintenance.
Version 0.1.2 is a non-stable major release, which signals an immature API and a higher likelihood of breaking changes.
The sole workflow is fully analyzed and has read-only permissions with no audit findings, but both of its 2 action references are unpinned, reducing build reproducibility.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.2|^8.0 | — | — |
symfony/finder Version ^7.2|^8.0 | — | — |
symfony/string Version ^7.2|^8.0 | — | — |
symfony/console Version ^7.2|^8.0 | — | — |
nikic/php-parser Version ^5.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.