The stable release line and organization-backed repository provide useful continuity. No commits were recorded in the last three months, and the sole workflow uses an unpinned action, leaving maintenance and build-hygiene concerns.
70%
Total Score
75
100
75
No commits or active maintainers were recorded in the last three months, which lowers confidence in current maintenance even though the repository was pushed more recently than that window.
The repository has no security policy, leaving vulnerability-reporting expectations unclear; this is a transparency gap rather than evidence of unsafe code.
The only workflow is fully unpinned, with 1 of 1 action references unpinned, which weakens build reproducibility. Its pull_request_target trigger has no untrusted checkout or script-injection sink, so this is not a severe workflow risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
aeon-php/calendar Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.