Tests, a clear README, release notes for this version, and a declared MIT license make integration and reuse straightforward. The organization owns the repository, though recent work comes from one contributor and workflow actions are unpinned.
80%
Total Score
88
100
75
All 12 recent commits came from one contributor, creating a meaningful single-person continuity risk despite the repository being organization-owned.
The repository has no security policy, which reduces transparency about vulnerability reporting and handling, although active releases and recent commits provide compensating maintenance evidence.
The sole workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, leaving avoidable dependency-integrity and reproducibility risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^3.0 | — | — |
zozlak/logging Version ^1 | — | — |
guzzlehttp/guzzle Version ^7 | — | — |
zozlak/http-accept Version ^1 | — | — |
acdh-oeaw/arche-lib Version ^7.6.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.