The MIT license, repository tests, changelog, and small dependency surface are positives. The workflow leaves two actions unpinned and the project has no security policy; maintenance cannot yet be demonstrated.
67%
Total Score
50
100
88
67
This is a very new package, with only two releases published within minutes and no longer-term release pattern. That limits evidence of sustained maintenance, though the absence of history is expected for a new project.
No commits or active maintainers were recorded over the last three months. Because the project is only hours old, this is weak evidence of abandonment but still leaves maintenance capacity unproven.
Composer build tooling is present, but no security scanning tool was detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no published security policy, leaving the process for reporting and handling vulnerabilities unclear.
The single workflow was fully analyzed without dangerous triggers or audit findings, but both of its two action references are unpinned. That leaves dependency updates less reproducible.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.