Integration tests for PocketMine-MP plugins: a real server, simulated players, one command.
68%
Total Score
caution
All workflow actions are unpinned, and the project is only a day old despite strong recent PR activity.
Registry publishing is controlled by one maintainer, which creates some continuity risk; repository activity provides partial evidence of active ownership but not a broader maintainer base.
The package has 9 releases in about 1 day, showing active delivery but also an unusually new and rapidly changing project with little history.
No commits or active maintainers were recorded over the last 3 months, which conflicts with the recent release and pull-request activity and weakens confidence in the maintenance measurement.
v0.7.0 is not a prerelease, but the pre-1.0 version indicates the API and behavior may still change materially.
All 18 analyzed action references are unpinned, and the audit found three high-confidence template-injection findings in plugin.yml; with no untrusted checkout or injection trigger, these remain workflow-hygiene concerns rather than standalone severe risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.