Tests, release notes, and an organization-owned repository provide useful maintenance and transparency signals. The lack of security scanning and completely unpinned workflow actions leave avoidable supply-chain hygiene gaps.
68%
Total Score
75
86
50
The package has nine releases since October 2022, but none in the last 12 months and the latest registry release was in May 2025; this indicates slowed release maintenance.
There were no commits or active maintainers in the three months before collection, which weakens evidence of current development activity, although the recent repository push is a compensating signal.
Composer build tooling is present, but no security-scanning tool was detected, leaving a maintenance and supply-chain hygiene gap.
The README provides a security contact, but the repository has no formal security policy file; this is a modest transparency gap for future vulnerability handling.
Both workflows were fully analyzed with no dangerous findings or broad write permissions, but all seven action references are unpinned, reducing build reproducibility and trust.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
symfony/mailer Version ^6.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.