The package has useful documentation, organizational backing, and no install-time scripts. Its small dependency set is helpful, but the lack of recent maintenance and weak workflow security hygiene make adopting this release a liability.
40%
Total Score
50
100
75
75
The package has 85 releases, but none in the last 12 months; its latest release was in March 2024, indicating prolonged release inactivity.
The repository recorded zero commits and zero active maintainers in the last 3 months, reinforcing the abandonment risk despite the repository not being archived.
Composer build tooling is present, but no security-scanning tooling was detected, which weakens ongoing supply-chain hygiene alongside the workflow findings.
The linked repository has no security policy, leaving vulnerability-reporting and response expectations undocumented; no provided signal compensates for this gap.
All 24 analyzed action references are unpinned, one workflow has top-level write permissions, and a high-confidence medium-severity archived action plus high-confidence ad hoc package installs were found.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
commongateway/corebundle Version ^1.2.68 | <2.0 | — | — |
common-gateway/customer-notifications-bundle Version ^0.0.40 | < 1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.