It has a clear MIT license, tests, release notes for this version, and organization backing. The small dependency set and Dependabot are helpful, but the lack of a security policy leaves less guidance for incident handling.
68%
Total Score
75
100
93
75
The package has existed for over 8 years with 15 releases, but only one release in the last 12 months suggests a slow maintenance cadence. The recent 3.0.6 release and release notes provide some compensating evidence.
There were no commits and no active maintainers in the last three months, which is a meaningful maintenance concern. The recent release and repository push provide limited evidence that the project is not abandoned.
No security policy was found, leaving consumers without a documented process for reporting vulnerabilities or understanding security response expectations.
All three workflows were analyzed with no dangerous sinks or audit findings, but all 9 action references are unpinned, weakening build reproducibility and update integrity. The absence of top-level permissions is acceptable on its own.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/clock Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.