Clear documentation, licensing, and recent repository work provide useful support. The release notes are present, but its API may still change before a stable version.
70%
Total Score
67
100
94
83
One contributor made all five commits in the last three months, giving the project a current bus factor of one. Organization backing provides some handoff capacity, but no second recently active contributor is shown.
The repository recorded five commits in the last three months, so maintenance has not stopped. However, all recent activity is concentrated in a single active maintainer, leaving limited visible redundancy.
The repository has no SECURITY.md or other detected security policy. That is a transparency gap for reporting vulnerabilities, although it does not by itself indicate abandonment.
v12.0.0-beta2 is explicitly a prerelease, so consumers should expect API or behavior changes even though prereleases make up only 10% of recent versions.
Both workflows were analyzed successfully with no audit findings, no untrusted checkouts, and no script-injection paths; one workflow scopes permissions at job level. All three referenced actions are unpinned, however, so their fetched revisions are not fixed for reproducible builds.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
grpc/grpc Version ^1.42 | — | — |
symfony/lock Version ~7 || ~8 | — | — |
symfony/cache Version ~7 || ~8 | — | — |
laravel/framework Version ^13.20 | — | — |
google/cloud-spanner Version ^2.10.5 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.