The package includes a clear MIT license, a substantial README, release notes, and no install-time scripts. Its source repository has no recent commits, lacks a security policy, and the workflow uses unpinned actions with a high-confidence template-injection finding.
20%
Total Score
75
100
79
75
Packagist marks the entire package as abandoned and points to a replacement repository, which is a direct warning against taking a new dependency on this package.
The repository recorded zero commits and zero active maintainers during the last three months, indicating stalled recent maintenance despite the recent push timestamp.
The repository name does not match the package name and its README does not mention the package, so the link does not clearly establish that this repository publishes the assessed package.
The repository has no security policy, leaving vulnerability reporting and response expectations undocumented for a library handling API credentials and bot integrations.
All three action references are unpinned, and the audit found a high-confidence template-injection issue plus an archived action. The workflow has no dangerous external trigger or untrusted checkout, so this is a hygiene concern rather than a standalone severe risk.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
symfony/cache Version ^7.3 | — | — |
psr/simple-cache Version ^3.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.