Declarative test runner for validation libraries with snapshot testing, fuzzing, benchmarking, and parallel execution
63%
Total Score
caution
Usable with caveats: maintenance activity has stalled and all workflow actions are unpinned.
Only one registry account has publish access. That is a thin publishing base for a user-owned project and increases continuity risk if that maintainer becomes inactive.
The repository is owned by an individual account rather than an organization, so there is no demonstrated organizational backing to offset the single-maintainer finding.
The repository recorded zero commits and zero active maintainers in the last three months. The recent push provides some counterevidence, but the current activity gap still lowers maintenance confidence.
The repository uses Composer and just for builds, but no security-scanning tools were detected. This is a moderate hygiene gap rather than evidence of abandonment.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, all 8 action references are unpinned, leaving workflow dependencies exposed to upstream changes.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/yaml Version ^7.4.6 || ^8.0 | — | — |
symfony/console Version ^7.4.6 || ^8.0 | — | — |
symfony/process Version ^7.4.5 || ^8.0 | — | — |
nunomaduro/termwind Version ^2.4.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.