The repository is licensed, tested, documented, and not archived. Its workflows use unpinned actions and include a high-confidence unpinned container image; the update hook also adds some execution risk.
61%
Total Score
50
100
81
75
This is the only release, published nearly three years ago, with no releases in the last 12 months. That substantially raises abandonment risk despite the repository remaining available.
The package declares a post-update command, which introduces code execution during dependency updates. No other provided signal shows that this hook is unsafe, so the concern is limited.
The repository recorded zero commits and zero active maintainers in the last three months. This is consistent with the old release history and suggests limited ongoing maintenance.
Version v0.0.1 is an early, pre-1.0 release, so compatibility and project maturity are less established than for a stable-major package.
All 32 analyzed action references are unpinned, and the audit found a high-confidence unpinned container image in the PHPUnit workflow. The workflows have no untrusted checkout or script-injection findings, which limits the overall impact.
We didn't find any vulnerabilities for this package.
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.