The MIT license, focused dependency set, and matching repository make the package easy to inspect and adopt. Its very young v0 line and lack of recent commits leave long-term maintenance unproven, while workflow references are not pinned.
62%
Total Score
75
100
86
50
The package is 222 days old with four releases, but all four were published within roughly one hour, leaving no demonstrated release cadence after the initial extraction.
The repository recorded zero commits and zero active maintainers in the last three months. With the latest push occurring on February 15, 2026, ongoing maintenance is not demonstrated.
The repository has no security policy. This is a transparency and vulnerability-reporting gap, although it is not severe enough by itself to make the release unfit.
Version v0.2.2 is a non-stable-major release, so the API may still change. It is not marked prerelease, which provides some compensating stability.
Both workflows were fully analyzed with no dangerous triggers, untrusted checkouts, script injections, or audit findings. However, all four action references are unpinned, which leaves build inputs less reproducible and weakens supply-chain hygiene.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
psr/event-dispatcher Version ^1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.