This is a generally healthy, actively maintained pre-1.0 package with clear MIT licensing, tests, a matching source repository, organizational backing, recent releases, and recent commits from two maintainers. Its main concerns are limited maturity and adoption signals, the absence of repository security scanning and a security policy, and a workflow using pull_request_target with top-level write permissions; these warrant review of the CI configuration but do not outweigh the evidence of active maintenance and package transparency.
82%
Total Score
88
100
83
70
One workflow uses pull_request_target, which can be security-sensitive even though no untrusted checkout or script injection was detected; this merits CI review.
There is only 1 open issue and 1 open pull request, but no issues or pull requests were created or merged in the last month; this is a modest maintenance-activity gap rather than evidence of abandonment.
The repository has only 4 stars and 1 fork, indicating limited adoption, but popularity is supporting evidence and does not by itself undermine a maintained package.
Composer build tooling is present, but no security scanning tools were detected, leaving a security-hygiene gap in repository automation.
No security policy was found in the repository, reducing transparency around vulnerability reporting and coordinated disclosure.
We didn't find any vulnerabilities for this package.
No maintainer information available.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.