The package includes a clear README, release notes, and no install-time scripts. One contributor owns all recent commits, while the workflow uses a broad write token and an unpinned action.
78%
Total Score
83
94
83
All 91 recent commits came from one contributor, leaving maintenance dependent on a single active developer. Organization backing partly offsets the handoff risk but does not remove it.
Composer build tooling is present, but no security scanning tool was detected. The security policy and strong organizational backing provide some compensation, so this is a minor hygiene concern rather than a major dependency risk.
The single workflow was fully analyzed with no injection or high-confidence audit findings, but it grants top-level write permissions and uses its only action unpinned. Those are supply-chain hygiene weaknesses without an untrusted trigger or sink.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.