The package is clearly licensed, documented, and backed by an organization with a matching repository and release notes. Its workflow uses seven unpinned actions, and no repository security policy was found, leaving maintenance and build hygiene concerns.
62%
Total Score
75
88
50
The package has 31 releases over about 3 years, with a historical median interval of roughly 8 days, but it has had no release in the last 12 months. This is a meaningful recent slowdown despite the previously active cadence.
The repository recorded 0 commits and 0 active maintainers in the past 3 months. Although the repository was pushed recently according to repository_archived, the measured recent commit activity still indicates limited visible maintenance.
No security policy was found in the repository. This weakens vulnerability-reporting transparency, although it is a process gap rather than evidence that the package is unsafe.
The complete audit found no dangerous triggers, sinks, or high-severity findings, but all 7 action references are unpinned. That is a build-reproducibility and supply-chain hygiene gap, not a severe risk by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/cache Version ^3.0 | — | — |
nesbot/carbon Version ^3 | — | — |
decodelabs/atlas Version ^0.14 | — | — |
psr/simple-cache Version ^3.0 | — | — |
decodelabs/dictum Version ^0.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.