The repository has no security policy or scanning, and all six workflow actions are unpinned. Those hygiene gaps are offset by recent releases, an unarchived repository, tests, documentation, and a matching MIT license.
78%
Total Score
75
100
94
50
The repository had zero commits and zero active maintainers in the last three months. This suggests limited current development activity, though the release history shows recent publishing.
Composer build tooling is present, but no security-scanning tool was detected. That is a modest transparency and maintenance-hygiene gap, not evidence that the package is unsafe.
The repository has no security policy. This weakens vulnerability-reporting transparency, although the package's tests, documentation, and recent releases provide compensating project evidence.
The single workflow was fully analyzed with no detected untrusted checkouts, script injection, or audit findings. However, all six action references are unpinned, which leaves avoidable update-integrity risk; the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
zozlak/rdf-constants Version ^1 | — | — |
sweetrdf/rdf-interface Version ^2 | ^3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.