The repository is actively developed, tested, and backed by Composer and Psalm, with a second active contributor. Its small contributor base and absent security policy add maintenance and transparency concerns.
68%
Total Score
75
93
67
The artifact includes MIT license text and a repository license, but the manifest declares the release proprietary; that mismatch makes the terms unclear for adopters.
Two contributors are active, but the leading contributor accounts for about 62% of recent commits, leaving some concentration risk; the second contributor provides partial compensation.
No repository security policy was found, reducing transparency around vulnerability reporting for a web application.
All 34 analyzed action references are unpinned, and the workflow contains medium-confidence template-injection findings. The cache-poisoning findings are low confidence and count only as hygiene, but the unpinned references are a real reproducibility concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.