Recent commits and two active contributors show ongoing maintenance, while MIT licensing, repository tests, and release notes improve transparency. The lack of a security policy is a minor gap.
78%
Total Score
75
100
93
50
Two contributors are active, but one accounts for six of seven recent commits, leaving maintenance somewhat concentrated.
Composer build tooling is present, but no security scanning tool was detected, leaving a modest supply-chain hygiene gap.
The repository has no security policy, so vulnerability-reporting and response expectations are not documented.
All four workflows were analyzed without untrusted triggers, injection findings, or write permissions, but all eight action references are unpinned, reducing build reproducibility and update integrity.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0|~2.0|~3.0 | — | — |
psr/http-message Version ~1.0|~2.0 | — | — |
symfony/polyfill-php80 Version ~1.30.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.