The repository remains identifiable and the package includes a useful README, but its maintenance trail is thin. Unpinned workflow actions and no security policy add smaller transparency and supply-chain concerns.
52%
Total Score
50
60
50
The package has only 3 releases, with none in the last 12 months and the latest released in April 2021. This is a substantial maintenance concern despite the repository receiving a later push.
The repository had no commits and no active maintainers in the measured 3-month period. A last push in July 2024 shows it is not archived, but does not demonstrate current maintenance.
Composer is used for the build, which is appropriate for this package, but no security-scanning tooling was detected. This is a modest transparency and maintenance gap.
The repository has no security policy, leaving no documented route for reporting vulnerabilities. This is a transparency gap for a package that integrates external feed data.
The current v0.2.3 release is not marked as a prerelease, but the 0.x major version signals a less mature compatibility commitment. Its non-prerelease status partly offsets that concern.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
typo3/cms-core Version ^8.7 | — | — |
digedag/rn-base Version ^1.13.0 | — | — |
digedag/cfc-league Version ^1.6.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.