The package includes a clear README, repository tests, MIT licensing, and Psalm checks. Its small dependency surface and organization backing improve confidence; pin 2.3.0 if adopting.
64%
Total Score
67
100
94
75
The package has had no release in the last 12 months, and its latest release was about 21 months ago. This indicates slowing maintenance, though the package has an established release history.
There were no commits and no active maintainers in the last three months, consistent with a currently inactive project and increasing abandonment risk.
No issues or pull requests were opened or merged in the last month, and three issues remain open. This is a modest sign of low current activity rather than a severe project failure.
The repository has no security policy, leaving the process for reporting vulnerabilities unclear. This is a transparency gap, but it is less significant than the maintenance slowdown.
All six workflows were analyzed with no dangerous triggers, untrusted checkouts, or audit findings. However, all 13 action references are unpinned, which leaves avoidable workflow supply-chain hygiene risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cycle/database Version ^2.11.3 | — | — |
cycle/migrations Version ^4.2.4 | — | — |
cycle/schema-builder Version ^2.11.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.