一個基於專案的資料庫補丁管理工具
62%
Total Score
caution
Usable with caveats: no releases or commits since 2022 make maintenance uncertain.
The package has made only two releases, both in July 2022, with no releases in the last four years. This is a meaningful maintenance concern for a dependency, although the package's narrow scope may reduce change frequency.
There were no commits and no active maintainers in the last three months, consistent with the repository's last push being in September 2022. This materially raises abandonment and support risk.
Composer is used for builds, but no security scanning tooling is present. For a small package this is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all three action references are unpinned. The missing top-level permissions block is acceptable on its own, while unpinned actions remain a minor reproducibility concern.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.