A small organization-backed team is actively committing, with repository tests and security scanning in place. The workflow leaves both actions unpinned and the repository has no security policy.
68%
Total Score
100
93
50
The package has had no registry release in nearly seven years, with zero releases in the last 12 months. Recent repository activity partly offsets the stale published release history, but the registry cadence remains a maintenance concern.
The repository has no security policy, leaving disclosure and response expectations undocumented. This is a transparency gap, but it is not severe on its own.
The single workflow was fully analyzed with no dangerous triggers, untrusted checkouts, script injection, or audit findings. However, both action references are unpinned, reducing build reproducibility and supply-chain control.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/event-dispatcher Version >=2.8.26 | — | — |
detain/myadmin-plugin-installer Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.