The project includes tests, a license, and a matching repository, but its README is effectively empty and workflow actions are unpinned. Ongoing repository activity helps, though the one-release history remains a meaningful adoption concern.
61%
Total Score
75
75
Tests are present and the exact release has GitHub release notes, but the published README contains only one character, leaving consumers without meaningful package guidance.
This package has only one release, 0.0.1, published about 17 months ago, with no releases in the last 12 months. That leaves limited evidence of release maturity and ongoing maintenance.
The repository has no security policy. This is a transparency and maintenance gap, although it is less severe for a small package with no reported workflow audit findings.
Version 0.0.1 indicates an early-stage API even though it is not marked as a prerelease. The lack of a stable major version increases compatibility uncertainty.
Both workflows were analyzed with no injection, untrusted checkout, permission, or severity findings, and one workflow scopes read-only permissions. However, all three action references are unpinned, reducing build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
nyholm/psr7 Version ^1.8.2 | — | — |
psr/http-message Version ^1.1 || ^2.0 | — | — |
symfony/filesystem Version ^6.4 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
league/mime-type-detection Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.