Healthy and suitable to use, with a small operational caveat: it is actively maintained, clearly licensed, documented, and released with notes, but its Composer install and update scripts deserve review before adoption.
82%
Total Score
100
100
100
75
Composer post-install and post-update scripts run automatically, which increases review requirements because installation can execute package-controlled actions. This is a genuine supply-chain hygiene concern even though the package is primarily Markdown.
One workflow has no top-level permissions declaration, which is less explicit than ideal; however, no workflow declares top-level write permissions and another uses read-only permissions, limiting the concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sandermuller/boost-core Version ^1.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.