The package has a clear README, tests, matching MIT licensing, and a repository that matches the package. Organization ownership and a recently merged pull request help, but maintenance evidence is limited and workflow references are not pinned.
60%
Total Score
83
88
67
This is the only registry release, published nearly four years ago, with no releases in the last 12 months. That limits evidence of ongoing release maintenance, despite the repository showing some recent activity.
There were no commits and no active maintainers in the last three months. Although this does not prove abandonment, it weakens the evidence that maintenance is currently active.
The repository uses Composer for builds, but no security scanning tooling was detected. This is a modest transparency and maintenance gap rather than a severe risk.
No repository security policy was found. That reduces disclosure transparency, though it is not by itself evidence that the package is unsafe to depend on.
Both workflows were analyzed successfully with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 8 action references are unpinned, leaving build inputs less reproducible and less resistant to upstream changes.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.