Frequent releases and five active contributors support continued maintenance. High-confidence workflow findings widen automation access, while unpinned tools weaken build reproducibility.
58%
Total Score
100
100
88
83
Packagist marks the package abandoned at package scope, although the listed replacement is the same package and the release history shows current publication activity. This is a substantial adoption and continuity warning rather than proof that the code is unfit.
All 13 workflows were analyzed, but ten actions use unpinned tools and high-confidence findings grant blanket GitHub App permissions in three workflows. High-confidence template-injection findings are also present, though no pull_request_target, workflow_run, or untrusted checkout trigger was reported.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
revolt/event-loop Version ^1.0.9 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.