The package includes a license, README, release notes, tests in the repository, and a security policy. Its workflows use six unpinned actions, while repository activity was absent in the last three months and installation runs a post-install script.
58%
Total Score
50
86
75
The package runs a post-install-cmd script, adding install-time behavior that consumers must trust. No provided signal shows that this script is dangerous, so this is a moderate hygiene concern rather than a severe risk.
The package has 71 releases over about 2 years, but only one release in the last 12 months. The recent v8.2.6 release provides some evidence of continued publishing, but the overall cadence is now thin.
The repository recorded zero commits and zero active maintainers in the last three months. The same-day release and repository push provide limited compensating evidence, but do not show sustained maintenance.
The repository has zero stars, zero watchers, and one fork, providing little external evidence of adoption or review. Popularity is supporting evidence only, so this modestly lowers confidence in project maturity rather than determining the verdict.
All six analyzed action references are unpinned, which weakens build reproducibility and supply-chain hygiene. The audit was complete and found no untrusted checkouts, script injection, or high-severity findings.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1.0 || ^2.0 || ^3.0 | — | — |
setasign/fpdi Version ^2.1 | — | — |
psr/http-message Version ^1.0 || ^2.0 | — | — |
myclabs/deep-copy Version ^1.7 | — | — |
paragonie/random_compat Version ^1.4|^2.0|^9.99.99 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.