The small dependency surface, tests, README, and MIT license support straightforward integration. A single recent contributor, absent security policy, and weak workflow pinning leave some maintenance depth and build hygiene unproven.
78%
Total Score
83
100
94
67
All four recent commits came from one contributor. Organization backing provides some handoff capacity, but no second recent contributor is shown to share maintenance responsibility.
Composer build tooling is present, but no security scanning tool was detected, leaving security-oriented maintenance practices less visible.
The repository has no SECURITY.md policy, so vulnerability reporting and response expectations are not documented.
The only workflow is fully analyzed and has no untrusted-trigger or script-injection issue, but all three action references are unpinned; the low-confidence cache-poisoning finding is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.