The package includes a clear README, a matching MIT license, and release notes for this version. Recent releases and commits show active maintenance, but one contributor carries all recent work and workflow actions are unpinned.
78%
Total Score
75
100
67
All 7 recent commits came from one contributor, so maintenance depends heavily on a single person.
The repository has no published security policy, leaving vulnerability-reporting and response expectations unclear.
The single workflow was fully analyzed with no injection or high-severity findings, but all 4 action references are unpinned, weakening build reproducibility and update control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.1.2 || 2.0 | — | — |
seld/jsonlint Version ^1.11 | — | — |
webmozart/assert Version ^1.12.1 || ^2.1 | — | — |
laminas/laminas-db Version ^2.20.0 | — | — |
laminas/laminas-log Version ^2.17.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.