Tests, release notes, and a lightweight dependency profile provide useful support. Unpinned workflow actions and the lack of a security policy or scanning reduce transparency and build confidence.
58%
Total Score
50
70
50
The package has 8 releases since August 2018, but none in the last 12 months and the latest was over two and a half years ago, indicating meaningful maintenance risk.
There were no commits or active maintainers in the last three months, weakening evidence of ongoing maintenance and increasing the risk that issues will remain unaddressed.
Composer is used for builds, but no security scanning tooling is configured, leaving an avoidable gap in project transparency.
The repository has no security policy, so users have no documented vulnerability-reporting process.
Version 0.5.1 is not a stable major release, although it is not marked as a prerelease and recent releases have not used prerelease versions.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.