Clear documentation, tests, and release notes make the package straightforward to evaluate and maintain. Its small audience and single registry publisher limit independent validation, but recent project activity and security tooling offset that concern.
82%
Total Score
75
100
100
75
Composer post-install and post-update scripts run during dependency operations. This is a modest supply-chain and installation-behavior concern because those scripts execute automatically, although no severe behavior is shown here.
Only one account has registry publishing access. That is a narrow publishing control base, but the repository shows two active contributors and the owner is actively releasing.
The package and repository are owned by the same individual account rather than an organization. This limits institutional backing, although recent commits and releases show active personal maintenance.
All six workflows were analyzed with no untrusted checkout or script-injection findings, and four use read-only permissions. However, all 27 action references are unpinned, one workflow has top-level write permissions, and a high-confidence low-severity audit found an ad hoc package installation; these are workflow hygiene cautions, not standalone severe risks.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sandermuller/boost-core Version ^1.6 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.