Healthy and actively developed, with strong documentation, tests, frequent releases, and recent work from two contributors. Install with normal caution because the repository has little adoption and lacks a security policy and explicit workflow permissions.
82%
Total Score
90
100
89
80
Only one registry publishing account is listed, which is a modest publishing continuity concern. The linked repository nevertheless shows two active contributors, partly compensating for the narrow registry maintainer list.
The repository has only 1 star, 0 forks, and 0 watchers, so there is little external adoption evidence. This is supporting evidence rather than a decisive health problem because other activity signals are strong.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning reduces assurance, though it is not by itself evidence of an unhealthy project.
No repository security policy was found, leaving vulnerability-reporting expectations and response procedures undocumented.
The only workflow lacks top-level token permissions. Although no write permissions were explicitly requested, declaring least-privilege permissions would make CI behavior more transparent.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.