The code is small and clearly licensed, with a matching repository and straightforward dependencies. Its lightweight documentation is supplemented by release notes, but this is not a strong choice for projects needing robust ongoing maintenance assurance.
68%
Total Score
75
100
50
The repository recorded zero commits and zero active maintainers in the last three months. The recent release partly offsets this, but the lack of ongoing visible activity is a maintenance caution.
The repository has no published security policy. For a small annotation package this is a limited transparency gap, but it still makes vulnerability reporting less clear.
The sole workflow was fully analyzed with no dangerous triggers or audit findings, but all four action references are unpinned. That leaves avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
spiral/attributes Version ^2.8|^3.0 | — | — |
doctrine/annotations Version ^1.11|^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.