Clear licensing, repository tests, release notes, and organization backing improve confidence in the package. Pin this version and expect limited maintenance attention until a newer release appears.
62%
Total Score
75
94
50
The package has had 3 releases since March 2023, but none in the last 12 months; the latest release was over two years ago. This is a meaningful maintenance concern despite a stable release history.
The repository had no commits and no active maintainers in the last 3 months. Although it was pushed in February 2025, the recent inactivity lowers confidence in ongoing maintenance.
No security policy is present in the repository, leaving vulnerability-reporting expectations unclear. This is a transparency gap, not evidence that the package is unsafe.
Both workflows were fully analyzed with no injection or high-severity findings, but all 4 action references are unpinned. That weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
deployer/deployer Version ^7.2 | — | — |
codenamephp/deployer.base Version ^3.0 | — | — |
codenamephp/platform.secretsmanager.base Version ^1.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.