The project has a long release history, clear documentation, tests, and a security policy. Its small user base and lack of automated security scanning leave less independent assurance.
68%
Total Score
100
100
88
100
The package has existed for over 11 years with 38 releases, but only one release in the last 12 months. The recent 4.3.0 release provides some evidence of continued maintenance, while the slower recent cadence warrants caution.
Composer is used for builds, but no repository security-scanning tool was detected. That is a modest assurance gap, though it is not evidence of a defect by itself.
The single workflow was fully analyzed with no injection sinks or audit findings, but both of its two action references are unpinned. Pinning them would improve build reproducibility and reduce action-substitution risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
curl/curl Version ^2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.