The package has clear documentation, tests, release notes, and a matching source repository. Its small project footprint, no recent registry releases, and workflow audit issues call for caution about long-term maintenance and automation hygiene.
61%
Total Score
75
100
94
83
Only three releases have been published since November 2024, with no releases in the past 12 months. The roughly 21-day median interval shows an initially active project, but the subsequent release gap lowers confidence in ongoing maintenance.
The repository recorded zero commits and zero active maintainers during the last three months. This is a direct maintenance warning, although the later recorded push shows the project is not wholly abandoned.
The repository has no SECURITY.md or other detected security policy. That is a transparency gap for a package intended to interact with an administrative API, though it does not by itself show unsafe code.
All 12 analyzed action references are unpinned, and three workflows grant top-level write permissions. The audit also reports a high-confidence bot-conditions finding in the Dependabot auto-merge workflow; there is no untrusted checkout or script-injection finding, so this is workflow hygiene risk rather than a severe supply-chain verdict.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
saloonphp/saloon Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.