The source project has recent work from two contributors, organization backing, tests, and security tooling. The registry release is stale and both workflow actions are unpinned, so pinning this version should be deliberate.
68%
Total Score
100
100
93
75
The latest registry release is nearly seven years old, with no releases in the last 12 months and only two releases overall. Recent repository work partly offsets abandonment concerns, but the published version may be stale.
The repository has no published security policy. This is a transparency and vulnerability-reporting gap, although it is a smaller concern than the stale registry release.
The single workflow was fully analyzed and has no untrusted checkout or script-injection findings, but both referenced actions are unpinned. That leaves avoidable workflow supply-chain exposure.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
symfony/event-dispatcher Version >=2.8.26 | — | — |
detain/myadmin-plugin-installer Version dev-master | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.