MIT licensing, a small dependency set, repository tests, and Psalm scanning support straightforward adoption. Maintenance is concentrated in one contributor, and both workflow action references are unpinned; the organization backing and recent releases reduce that concern.
78%
Total Score
83
100
100
67
All 7 recent commits came from one contributor, leaving maintenance dependent on a single active individual. Organization backing partly compensates by providing potential handoff capacity.
The repository has no security policy, which leaves vulnerability-reporting expectations less transparent for consumers.
Both workflows were analyzed cleanly with no untrusted checkouts, script injection, or audit findings. However, both of the two action references are unpinned, which is a supply-chain hygiene caution.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.