The package is clearly documented, tested, licensed, and backed by a matching organization repository. Its release pace is sparse, recent commit activity is absent, and workflow dependencies are unpinned, so maintenance and build-reproducibility concerns remain.
68%
Total Score
83
100
88
83
Only 3 releases have appeared across 989 days, with 1 release in the last 12 months and a median interval of about 446 days; this indicates a slow maintenance pace, though the latest release is recent.
There were 0 commits and 0 active maintainers in the last 3 months, which weakens confidence in ongoing maintenance; the recent release and non-archived repository partly offset this.
Composer build tooling is present, but no security scanning tools were detected, leaving a modest transparency and maintenance-hygiene gap.
The repository has no security policy, reducing transparency about how vulnerabilities should be reported and handled.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, both of its two action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.