The release has tests, a substantial README, and published release notes, but the repository shows no commits in the last three months. Broad workflow permissions and completely unpinned actions add maintenance and build-hygiene concerns.
38%
Total Score
75
67
100
Packagist marks the entire package as abandoned and names ta-lib/ext-ta-lib as its replacement. That substantially weakens confidence in taking a dependency on this package, even though the release itself is not individually withdrawn.
Only two releases exist over roughly seven months, with the latest released about seven months ago. This is limited history for judging long-term maintenance, though the package is still relatively young.
The repository recorded zero commits and zero active maintainers over the last three months. That is consistent with a project that may have stopped receiving maintenance.
The linked repository name does not match coral-media/ext-ta and its README does not mention the package. Organization backing makes a monorepo or publishing-layout explanation possible, but the package-to-source relationship is still less transparent.
Both analyzed workflows grant top-level write permissions, and all 10 action references are unpinned. No untrusted triggers, injection sinks, or auditor findings were reported, so this is a hygiene concern rather than a severe workflow risk.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.