It has a clear license, useful documentation, tests, and a focused dependency footprint. The repository is active and correctly tied to the package, but its small public footprint limits confidence in long-term support.
72%
Total Score
100
79
75
Only 3 releases have been published across 494 days, with 1 release in the last 12 months and a median interval of about 91 days. This suggests a small, slower-moving project rather than active development.
Composer is used for builds, but no security scanning tools are reported. For a small contracts package this is a modest transparency gap, not a severe dependency risk.
The repository has no published security policy. This weakens the project's security-response transparency, although the package's limited scope reduces the practical impact.
Version 0.0.3 is not a stable major release, so compatibility guarantees may still be limited. It is not marked as a prerelease, which partly offsets that concern.
Both workflows were analyzed without failed files or dangerous-trigger sinks, and one uses read-only permissions. However, all 3 analyzed action references are unpinned, leaving workflow inputs vulnerable to silent upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/dependency-injection Version ^7.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.