The repository has had no commits or active maintainers in the last three months, despite two releases in the last year. All four workflow actions are unpinned and the project has no security scanning, while organization backing, licensing, tests, and release documentation support continued use.
68%
Total Score
75
100
93
75
There were zero commits and zero active maintainers in the last three months, a meaningful sign of slowed maintenance. The recent release history partly offsets this, but does not remove the abandonment concern.
The repository uses Composer and Make, but no security scanning tools were detected, leaving a maintenance and security-hygiene gap.
No security policy was found in the repository, which reduces transparency for reporting and handling vulnerabilities.
Both workflows were analyzed completely with no dangerous triggers, untrusted checkouts, or audit findings. However, all 4 action references are unpinned, weakening build reproducibility and supply-chain hygiene; the absence of top-level permissions is acceptable on its own.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
async-aws/core Version ^1.9 | — | — |
symfony/polyfill-uuid Version ^1.13.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.