The project includes tests, release notes, a matching repository, and a current stable release. Maintenance is quiet between releases, and its two workflow actions are unpinned; no security scanning is configured.
78%
Total Score
88
100
88
75
The package has existed since August 2021 and has four releases, but only one release occurred in the last 12 months with a median interval of about 238 days. This indicates slow but not clearly abandoned maintenance.
There were zero commits and zero active maintainers in the last three months. The recent release and current repository push provide some compensation, but ongoing development activity is still limited.
Composer build tooling is present, but no security scanning tools were detected. The missing scanning is a modest transparency and maintenance gap, not a standalone adoption blocker.
The repository has no security policy. For a small query-building library this is a transparency gap, though the package does not show other severe security-health indicators.
The single workflow was fully analyzed with no high- or medium-confidence findings, dangerous triggers, untrusted checkouts, or script injections. Both of its two action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.