The organization has five active contributors and the repository was updated recently. The release is licensed, documented, and has no install scripts or audited workflow findings.
78%
Total Score
100
100
88
75
Only one release exists, published about 6 years and 10 months ago, which limits evidence of registry maintenance. Recent repository commits and organizational backing partly compensate for that stale release history.
Composer build tooling is present, but no security scanning tools were detected; this is a minor transparency and hygiene gap rather than a dependency-blocking risk.
The repository has no security policy, leaving vulnerability-reporting expectations unspecified. This is a minor transparency gap for an otherwise actively maintained project.
The sole workflow was fully analyzed with no audit findings or untrusted-code sinks. Two of four action references are unpinned, which is a modest reproducibility and supply-chain hygiene concern.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.