Unpinned workflow actions and no security scanning reduce operational confidence. The repository has tests, an MIT license, a minimal dependency profile, and no install scripts.
63%
Total Score
75
100
72
75
The artifact omits a readme, but the repository has tests and this exact version has a GitHub release; the missing artifact changelog is normal packaging practice.
This package has only one release, published 219 days ago, so there is little release history to demonstrate sustained maintenance.
There were zero commits and zero active maintainers in the last three months, leaving ongoing maintenance unproven after the initial release.
The repository has zero stars, forks, and watchers. Popularity is only supporting evidence, but these counts provide no external adoption signal for this new package.
Composer build tooling is present, but no security scanning tools were detected, leaving a repository hygiene gap.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.