The source includes tests, a changelog, and matching MIT licensing. Its workflow uses read-only permissions, but all three actions are unpinned.
45%
Total Score
50
100
81
100
The package has only one release, published more than three years ago, with no releases in the last 12 months. This leaves little evidence of ongoing maintenance.
The repository recorded no commits and no active maintainers in the last three months, matching the long release gap and increasing abandonment risk.
One registry maintainer is consistent with a small user-owned project, but it provides little maintenance redundancy alongside the absence of recent releases and commits.
The repository uses Composer build tooling, but no security scanning tools were detected. For this small package, the missing scanner is a secondary hygiene gap rather than the main risk.
The workflow was fully analyzed, uses read-only permissions, and has no reported audit findings or untrusted checkout and injection patterns. However, all three action references are unpinned, leaving a modest reproducibility risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.