Only two commits came from one contributor in the last three months, and the repository has no security policy. The workflow is complete but uses two unpinned actions, increasing maintenance and build-integrity concerns.
63%
Total Score
50
92
50
One contributor made all commits in the last three months, giving the project a single-person operational dependency. The matching repository and package identity do not compensate for that concentration.
The repository had only two commits in the last three months. Recent activity exists, but the low volume suggests limited maintenance capacity for a package consumers may depend on.
The repository has no security policy. This is a transparency and response-process gap, although it is not by itself evidence that the package is unsafe.
The current v0.2.0 release is not a stable major version, so its API may still change. It is not marked as a prerelease, which partly offsets that concern.
The workflow audit completed cleanly with no untrusted checkout or script-injection findings, but both of its two action references are unpinned. That leaves the build exposed to moving action revisions.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psx/framework Version ^8.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.