A thin public footprint and no security policy reduce confidence for long-term use. Clear documentation, matching licensing, and a small dependency surface are reassuring.
70%
Total Score
75
100
89
50
The repository recorded no commits and no active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the recent release.
The repository has two stars, no forks, and one watcher. This is limited adoption evidence, though popularity is only supporting evidence for a small interface package.
Composer build tooling is present, but no security scanning tools were detected, leaving repository-level security hygiene less visible.
The repository has no published security policy, so users have no documented vulnerability-reporting or response path.
The sole workflow was fully analyzed with no dangerous audit findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own and there are no write-permission or untrusted-trigger findings.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.