The small runtime dependency set, MIT licensing, release notes, and organization backing support adoption. Unpinned GitHub Actions references add a modest reproducibility concern alongside the aging maintenance signals.
62%
Total Score
67
100
93
100
The package has 13 releases since January 2017, but its latest release was about two and a half years ago and there were no releases in the last 12 months. Its long history partly offsets the aging release cadence, but maintenance looks slow.
The repository had 0 commits and 0 active maintainers in the last 3 months, consistent with the absence of recent releases. The established project backing is reassuring but does not show current maintenance.
There were no new or closed issues or pull requests in the last month, while 3 issues and 3 pull requests remain open. This is a modest sign of limited current activity rather than evidence of abandonment on its own.
All 3 analyzed action references are unpinned, which weakens build reproducibility. The audit found no untrusted checkouts, script injection, dangerous triggers, or higher-severity findings, limiting this to a hygiene concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^4.0.0-alpha.1|^5.0.0-beta.1 | — | — |
symfony/mailgun-mailer Version ^6.0.3|7.0.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.