It has a clear MIT license, repository tests, a README, and only one runtime dependency. The workflow audit also found an unpinned container image, which weakens build reproducibility.
38%
Total Score
75
100
71
75
The package is marked as borrowing the identity of spatie/error-solutions, which has about 4,949,964 monthly downloads versus 8 for this package; that strongly suggests consumers may have wanted the lookalike instead.
The latest release was about 6 years ago, with no releases in the last 12 months. The short four-release history provides little evidence of sustained release maintenance.
The repository recorded no commits and no active maintainers in the last 3 months, despite being unarchived. This is meaningful abandonment risk for a dependency.
No repository security policy was found. This is a modest transparency gap, though the README provides a security contact.
All 7 action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in php-cs-fixer.yml. This weakens reproducibility and build integrity.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.