The project has had no commits in the past three months, and all seven workflow actions are unpinned. Clear licensing, tests and release notes provide useful transparency, while the repository remains active and unarchived.
72%
Total Score
75
100
94
75
No commits and no active maintainers were recorded in the past three months. Recent releases partly offset this, but the lack of current development lowers confidence in ongoing maintenance.
Composer build tooling is present, but no security-scanning tools were detected. This is a modest transparency and maintenance gap rather than a severe risk.
The repository has no security policy, leaving vulnerability-reporting expectations undocumented.
The single workflow was fully analyzed with no untrusted checkouts, injection findings, or dangerous triggers. However, all seven action references are unpinned, which weakens build reproducibility and supply-chain hygiene.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
decodelabs/lucid Version ^0.8 | — | — |
decodelabs/coercion Version ^0.3.5 | — | — |
decodelabs/fluidity Version ^0.3.7 | — | — |
decodelabs/exceptional Version ^0.6.3 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.