Clear licensing, a useful README, repository tests, and organization backing support adoption. The limited release history and absent security policy reduce confidence in long-term maintenance.
68%
Total Score
75
94
50
The package has existed for about 5 years, with 7 releases and one release in the last 12 months. The latest release is recent enough to show ongoing publishing, but the modest cadence limits maintenance confidence.
There were no commits and no active maintainers in the last 3 months. This is a meaningful maintenance warning, although the package had a release within the broader 12-month period.
The repository has no published security policy. This is a transparency gap for reporting and handling vulnerabilities, though it does not by itself show that the package is unsafe.
All 3 workflows were analyzed successfully and had no dangerous audit findings or untrusted checkouts. However, all 9 action references are unpinned, leaving build automation exposed to moving action versions.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
cycle/orm Version ^2.0 | — | — |
symfony/polyfill-php83 Version ^1.31.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.