The package has tests, an MIT declaration, and a matching source repository, but its maintenance record is thin. The workflows also use an unpinned container image, and no security policy or scanning tools are present.
55%
Total Score
50
93
67
The latest release was about four years and eight months ago, with no releases in the last 12 months. Only four releases exist, which limits evidence of ongoing maintenance.
The repository recorded zero commits and zero active maintainers in the last three months, providing no recent evidence of active development.
The repository has no security policy, and repo_tooling reports no security-scanning tools. This reduces transparency and makes vulnerability handling less clear.
All 8 analyzed action references are unpinned, and a high-confidence audit found a workflow using a floating container image tagged latest. The workflows have no untrusted triggers or script-injection findings, so this is a hygiene concern rather than a severe risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
atk4/core Version ~3.1.0 | — | — |
psr/container Version ^2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.