The library includes a focused test suite, a clear README, and release notes for this version. Its MIT declaration, minimal runtime dependencies, and read-only workflow permissions are reassuring, though the workflow uses unpinned actions.
67%
Total Score
50
100
88
67
The package has only two releases, both published on the same day, with no later release activity over its 317-day lifetime. This limits evidence of sustained maintenance.
There were no commits and no active maintainers in the past three months. Combined with the short release history, this is a meaningful maintenance concern.
The project uses Composer, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap rather than evidence of an unsafe release.
The repository has no security policy. That weakens the project's documented process for reporting and handling vulnerabilities.
The single workflow was fully analyzed, uses read-only permissions, and has no audit findings, but both action references are unpinned. Unpinned actions leave the build exposed to upstream reference changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.