The project has a clear README, repository tests, recent release notes, and no deprecation or archive flag. Its single-maintainer base, quiet recent commit history, missing security policy, and unpinned workflow actions leave meaningful maintenance and build-hygiene concerns.
65%
Total Score
50
94
67
Only one registry account has publish access. The repository is user-owned rather than organization-backed, so there is little visible publishing redundancy.
There were no commits and no active maintainers in the last three months, indicating currently quiet development despite the recent release and repository push.
Composer build tooling is present, but no security-scanning tool was detected, leaving a modest repository hygiene gap.
The repository has no security policy, so vulnerability reporting and disclosure expectations are less transparent for consumers.
All four workflows were analyzed without dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 16 action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.