The README, release notes, and matching repository make the package straightforward to adopt. Its small dependency surface and organization backing help, while the clean workflow audit reduces operational concern.
58%
Total Score
67
100
86
83
The registry declares GPL-3.0-or-later and the package README states GPLv2 or later, but the only detected artifact license is MIT in vendor/composer/LICENSE. That mismatch creates licensing ambiguity despite the package-level GPL declarations.
The package has 41 releases over roughly eight years, but none in the last 12 months; the latest release was about one year ago. Its long history partly offsets the recent release gap, but maintenance momentum appears reduced.
The repository recorded no commits and no active maintainers during the last three months. Although the repository was pushed recently and the project has a long release history, this indicates limited current development activity.
There were no new or closed issues or pull requests in the last month, with 12 issues and 2 pull requests still open. This suggests unresolved maintenance demand and little recent triage.
Both workflows were analyzed successfully with no audit findings, untrusted checkouts, or script injection, but all 4 action references are unpinned. The clean audit is positive; unpinned actions leave a modest reproducibility and supply-chain hygiene gap.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.