Directory snapshot, diff, and patch system useful for test fixtures.
82%
Total Score
70
100
89
80
One of four workflows uses pull_request_target, which warrants review because that trigger can expose privileged workflow behavior, but no untrusted checkout or script-injection patterns were detected.
Only one account has registry publish access. This is a caution for publishing continuity, though recent repository activity shows that the same maintainer is actively maintaining the project.
The repository is owned by an individual user rather than an organization, so there is no organizational maintenance-backing signal to offset the concentrated maintainer base.
One contributor made all 23 commits in the last 3 months, creating a meaningful bus-factor and continuity risk; the repository is user-owned rather than organization-owned, so there is no project-backing compensation.
The repository has only 1 star, 0 forks, and 0 watchers, indicating limited external adoption; popularity is supporting evidence rather than a decisive health measure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
sebastian/diff Version ^6.0 || ^7.0 | — | — |
alexskrypnyk/file Version ^1.2.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.