Clear documentation, licensing, and a minimal runtime dependency make adoption straightforward. The organization-backed repository includes tests and release notes, despite limited recent activity.
78%
Total Score
75
100
94
83
There were no commits and no active maintainers in the last three months. This is a meaningful recent-maintenance gap, although the release history shows activity within the last year.
Composer build tooling is present, but no security-scanning tooling was detected. That is a modest transparency and hygiene gap rather than evidence of abandonment.
The repository has no security policy. For a small library this is a limited disclosure-process gap, but it reduces transparency for reporting vulnerabilities.
All three workflows were analyzed, with no untrusted checkouts or script injection, but all seven action references are unpinned and the audit found a high-confidence unpinned container image. This weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.