The package has clear documentation, tests, an MIT license, regular releases, and active security tooling. Its young project relies on one contributor, and all three workflow actions are unpinned, so maintenance continuity and build reproducibility remain concerns.
68%
Total Score
83
100
94
75
One contributor made all 41 commits in the last 3 months, creating a real continuity risk; organization ownership provides some backing but no active second contributor is shown.
The repository has no published security policy, making vulnerability reporting and coordinated disclosure less transparent for a security-focused framework.
v0.13.0 is not a prerelease, but the package remains below major version 1, so its public interfaces may still change substantially.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, injection findings, or broad write permissions. However, all 3 action references are unpinned, weakening build reproducibility, while the missing top-level permissions block is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
latte/latte Version ^3.0 | — | — |
tracy/tracy Version ^2.10 | — | — |
symfony/yaml Version ^7.0 | — | — |
vlucas/phpdotenv Version ^5.6 | — | — |
phpmailer/phpmailer Version ^6.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.