It has a clear MIT license, a substantial README, repository tests, and no install-time scripts. The workflow audit also found an unpinned container image, and no security scanning is configured.
40%
Total Score
0
70
75
Only one release exists, and there have been no releases in roughly four years. That leaves little evidence of ongoing maintenance or compatibility work.
The repository recorded no commits and no active maintainers in the last three months, consistent with the release history showing roughly four years of inactivity.
The repository has no security policy, so there is no documented vulnerability-reporting process. This is a transparency gap, though the README provides a security contact address.
The latest version is still 0.0.1 and is not a stable major release. Combined with the lack of later releases, this indicates an unfinished or abandoned release line.
All 10 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image. There are no untrusted checkouts or script-injection findings, which limits the risk to workflow hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/mime Version ^5.2|^6.0 | — | — |
symfony/process Version ^5.2|^6.0 | — | — |
spatie/backtrace Version ^1.2 | — | — |
symfony/var-dumper Version ^5.2|^6.0 | — | — |
illuminate/pipeline Version ^8.0|^9.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.