Documentation, tests, licensing, and frequent releases make the package easy to evaluate. Its small recent contribution base and workflow hygiene leave more maintenance and build-integrity risk than a fully mature dependency.
68%
Total Score
67
100
93
75
All recent repository commits came from one contributor, leaving a concentrated maintenance path; organization backing provides some handoff capacity but no second active contributor is shown.
Only one commit was recorded in the last three months, so observed development activity is currently thin despite the frequent registry releases.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest security-process gap.
The repository has no published security policy, which reduces transparency about vulnerability reporting and response.
Both workflows were analyzed successfully, but all three action references are unpinned. The audit also found a high-confidence template-injection pattern in update.yml; template injection is a workflow hygiene concern here, while the absence of untrusted checkout and script-injection sinks limits escalation.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.