The package includes a substantial README, tests, Composer tooling, and a security policy. Its workflow uses read-only permissions, but all three actions are unpinned and the low-confidence cache warning merits review.
58%
Total Score
75
90
75
The latest release was about two years and six months ago, with no releases in the last 12 months. This is a meaningful maintenance concern, although the package may be intended as a stable project starter.
The repository recorded no commits in the last three months and no active maintainers during that period. The repository is not archived, but the recent inactivity weakens confidence in ongoing maintenance.
All three analyzed action references are unpinned, and the audit reported a low-confidence cache-poisoning pattern. Read-only permissions and the absence of untrusted checkouts or script injection reduce the risk, so this is a hygiene concern rather than a severe finding.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.4 | — | — |
charcoal/charcoal Version ^5.0 | — | — |
mustache/mustache Version ^2.14 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.