It has no security policy, and both workflow actions are unpinned. The MIT license, repository tests, and organization backing provide useful transparency and maintenance support.
67%
Total Score
75
90
50
The package has six releases over about three years, with one release in the last 12 months and a median interval of about 345 days; this indicates slow maintenance but not abandonment because the assessed version was released recently.
The repository recorded zero commits and zero active maintainers in the last three months, which weakens evidence of ongoing maintenance despite the recent registry release.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but both of its two action references are unpinned, creating a modest reproducibility and dependency-hygiene gap.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^1.0 | ^2.0 | — | — |
league/flysystem Version ^3 | — | — |
psr/http-factory Version ^1.0 | — | — |
siriusphp/validation Version ^3.0 | — | — |
psr/http-server-handler Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.