The package is still an early 0.x release, and all four workflow action references are unpinned. MIT licensing, a matching repository, Composer tooling, and Dependabot provide useful transparency, but no commits were recorded in about seven months.
55%
Total Score
50
83
67
There were zero commits and zero active maintainers in the last three months, while the last push was about seven months ago; this is a meaningful abandonment concern.
All five releases arrived within roughly two days, and there has been no later release over about seven months; this suggests an immature or stalled release history.
The repository has no security policy, which leaves vulnerability-reporting expectations unclear for a framework contracts package.
Version v0.2.3 is a non-stable-major 0.x release, so its interfaces may still change even though it is not marked as a prerelease.
Both workflows were fully analyzed with no dangerous audit findings, but all four action references are unpinned, leaving their versions exposed to upstream changes.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/container Version ^2.0 | — | — |
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.