The package is clearly documented, licensed, and provides release notes for this version. Its small workflow is fully audited, but the published release is old enough that pinning it requires extra maintenance caution.
60%
Total Score
75
81
88
The latest registry release was about four years ago, with no releases in the last 12 months. The linked repository was pushed more recently, but the registry artifact itself is stale.
There were no commits and no active maintainers in the last three months. Although the repository was pushed in 2025, the lack of recent activity weakens confidence in ongoing maintenance.
Composer is used as a build tool, but no security scanning tool was detected. This is a modest repository-hygiene gap rather than evidence that the release is unsafe.
Version 0.0.5 is not a stable major release, but it is not marked as a prerelease and recent releases have not been prerelease versions.
The single workflow was analyzed successfully with no detected injection, untrusted-checkout, or other audit findings. Its one action is unpinned, which leaves a small reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.