The focused test suite, clear documentation, and Composer security scanning support dependable maintenance. The project is young, releases are sparse, and all recent commits come from one contributor; unpinned workflow actions add a smaller supply-chain hygiene concern.
78%
Total Score
75
100
94
75
The package is only 160 days old and has two releases, with a median interval of about 138 days. That is limited evidence of sustained maintenance and warrants some caution, though it does not show abandonment.
One contributor made all three recent commits, creating a narrow current contributor base. The organization backing provides some handoff capacity, so this is a caution rather than a severe abandonment signal.
There were three commits in the last three months, showing recent activity, but all came from one active maintainer. The activity is present yet thin and concentrated.
No repository security policy is present. This is a transparency and issue-reporting gap, but the package's security scanning and tested source reduce its overall impact.
The single workflow was fully analyzed, uses read-only permissions, and has no untrusted checkouts or injection findings. Both action references are unpinned, which leaves a moderate workflow supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.