The package is clearly licensed and documented, with repository tests and a stable 1.6 release. Its lack of commits for over a year and unpinned workflow images make ongoing maintenance and build reproducibility concerns.
42%
Total Score
0
100
83
50
The package is 496 days old with seven releases, but none in the last 12 months; all releases arrived within a very short initial burst, leaving current maintenance unproven.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the absence of recent registry releases and raising abandonment risk.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a dependency used in application code.
All seven action references are unpinned, and the audit found a high-confidence, high-severity unpinned container image in the PHP code-style workflow. No untrusted checkout or script-injection path was found, which limits the concern to build hygiene rather than a severe workflow exposure.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.