Its small scope keeps dependencies simple, and the package includes clear consumer documentation and tests. The release cadence is modest and the repository lacks a security policy; all three workflow actions are also unpinned, though the audit found no dangerous triggers or findings.
78%
Total Score
100
100
83
75
The package has only two releases over 496 days, with one release in the last 12 months and a median interval of about 171 days. This shows some activity but only a modest maintenance record.
The repository has zero stars and forks and one watcher, so there is little external adoption evidence. For a small focused library, this is supporting caution rather than a standalone health failure.
Composer build tooling is present, but no security scanning tooling is reported, leaving a modest transparency and maintenance gap.
The repository has no security policy. This does not make the package unsafe by itself, but it weakens the project's stated process for handling vulnerabilities.
Both workflows were analyzed completely and produced no findings, with no untrusted checkout or script injection; however, all three action references are unpinned, which weakens build reproducibility.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.