The package is documented, tested in the repository, regularly released, and still receiving changes. Its small active contributor base, absent security policy, and unpinned workflow actions leave modest maintenance and build-integrity concerns.
72%
Total Score
83
88
75
One contributor made all five recent commits, creating concentration risk; the organization-owned repository provides some capacity to hand maintenance off, but no second active contributor is shown.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that this repository belongs to the published package.
The repository has one star and no forks or watchers. This is weak supporting evidence, but it does not outweigh the observed release and commit activity.
The repository has no security policy, leaving vulnerability reporting and response expectations less transparent than they could be.
The single workflow was fully analyzed with no dangerous triggers or audit findings, but all seven action references are unpinned, weakening build reproducibility and increasing dependency-change risk.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
cakephp/cakephp Version ^5.1 | — | — |
crustum/prompts Version * | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.